team-coordinate
Warn
Audited by Socket on Apr 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s coordination purpose is plausible, but its actual footprint is very broad: wildcard tool access, dynamic runtime prompt generation, background worker spawning, and shell-capable subagents. The biggest risk is indirect prompt injection and over-autonomous execution across generated worker roles. No direct credential theft or exfiltration is shown, but the capability set is disproportionate and high-risk for a generic orchestration skill.
Confidence: 84%Severity: 78%
Audit Metadata