claude-kimi-teammate
Warn
Audited by Socket on Jun 13, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior mostly matches its purpose, but it expands trust to an external AI CLI and creates an indirect prompt channel by injecting teammate output into the main agent as normal input. No clear malware or credential-harvesting behavior is present, yet the cross-agent delegation model and terminal-message brokering make this a medium-risk operational skill rather than a benign documentation-only helper.
Confidence: 100%Severity: 60%
Audit Metadata