BackstopJS Visual Regression Testing Automation

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose aligns with visual regression testing and the referenced BackstopJS project is real and well-scoped, with no obvious credential harvesting or exfiltration. The main concern is transitive installation: the skill asks the agent to install a third-party skill from `agentskillexchange/skills` rather than install/use BackstopJS directly, which adds supply-chain and inherited-permission risk disproportionate to a simple framework guide. Overall this looks coherent but medium-risk due to the extra trust layer.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 6, 2026, 01:03 AM
Package URL
pkg:socket/skills-sh/agentskillexchange%2Fskills%2Fbackstopjs-visual-regression-testing-automation%2F@f6ed6a00185517a1791a12bad617491ea9eeb525