agent-teams

Warn

Audited by Socket on Jul 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is mostly coherent for multi-agent software delivery, but it materially increases risk by enabling autonomous git push/PR creation and optionally relying on a third-party polyphony CLI with weaker provenance. No clear credential-harvesting or malicious exfiltration is shown, so this is not malware; the main concerns are external-action autonomy and moderate supply-chain trust.

Confidence: 80%Severity: 62%
Audit Metadata
Analyzed At
Jul 14, 2026, 04:18 PM
Package URL
pkg:socket/skills-sh/alinaqi%2Fmaggy%2Fagent-teams%2F@17718fa55d2492b49b91550ff1349e7ff2d0d652174ae24d357dc1e47c1bdff0
Security Audit — socket — agent-teams