create-teammate

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The overall workflow matches the stated purpose, but it is overpowered for that purpose: it mass-ingests sensitive workplace content, processes arbitrary external/untrusted text, and then auto-installs a generated skill into global agent trust paths. The main risks are transitive skill installation, prompt-injection through imported content, and privacy-heavy collection with insufficient trust and containment controls.

Confidence: 90%Severity: 78%
Audit Metadata
Analyzed At
Apr 9, 2026, 01:47 AM
Package URL
pkg:socket/skills-sh/LeoYeAI%2Fteammate-skill%2Fcreate-teammate%2F@41811c0f5bfdfde99cc6da95eb618ced18df9a25
Security Audit — socket — create-teammate