team-executor

Warn

Audited by Socket on Apr 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose largely matches its behavior, but it is overpowered for a 'lightweight' executor. The main risk is broad wildcard permissions plus dynamic loading of session role-spec content into spawned background agents with file and shell access, creating prompt-injection and high-impact automation risk. No clear credential harvesting, malware payload, or external exfiltration endpoint is shown.

Confidence: 84%Severity: 67%
Audit Metadata
Analyzed At
Apr 17, 2026, 01:13 AM
Package URL
pkg:socket/skills-sh/catlog22%2FMaestro-Flow%2Fteam-executor%2F@f7e139e63e349b8435717ea399a4a3f01a0aaaae