agent-team

Warn

Audited by Socket on Aug 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior mostly matches its purpose, but it combines broad repo ingestion, code/file modification, command execution, and autonomous multi-agent orchestration. The biggest concerns are the transitive trust chain (`npx skills add` from a personal GitHub repo) and the high prompt-injection surface from reading untrusted repo content while retaining write/exec capability. I see no clear credential theft or exfiltration, so this is not confirmed malware.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Aug 13, 2026, 05:42 PM
Package URL
pkg:socket/skills-sh/vtmocanu%2Fskills-nesttest%2Fagent-team%2F@4a72e67bd896587255b40f60e33d0a06cf88d005145d391d1a653cca54284693
Security Audit — socket — agent-team