agent-teams
Warn
Audited by Socket on Jul 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is mostly coherent for multi-agent software delivery, but it materially increases risk by enabling autonomous git push/PR creation and optionally relying on a third-party polyphony CLI with weaker provenance. No clear credential-harvesting or malicious exfiltration is shown, so this is not malware; the main concerns are external-action autonomy and moderate supply-chain trust.
Confidence: 80%Severity: 62%
Audit Metadata