team-harness

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s core behavior fits its stated purpose, and its referenced tooling is largely official, so there is little evidence of malware or credential theft. However, it meaningfully increases operational risk by encouraging autonomous multi-agent loops, broad permissions, and `--dangerously-skip-permissions`, while processing potentially untrusted project content with write/exec capability. This is a high-risk orchestration skill rather than a malicious one.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Apr 3, 2026, 09:29 AM
Package URL
pkg:socket/skills-sh/Derek-X-Wang%2Fskills%2Fteam-harness%2F@e58b7ad3b94e3b9f66cafc159e643e162d7acd0f