team-coordinate

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s coordination purpose is plausible, but its actual footprint is very broad: wildcard tool access, dynamic runtime prompt generation, background worker spawning, and shell-capable subagents. The biggest risk is indirect prompt injection and over-autonomous execution across generated worker roles. No direct credential theft or exfiltration is shown, but the capability set is disproportionate and high-risk for a generic orchestration skill.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/catlog22%2FMaestro-Flow%2Fteam-coordinate%2F@339c27dbe06444ff47eb5c41b5b183bbf6878e97