windows-qa-engineer

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/skill_installer.py

This code is a manifest-driven installer/configurator that performs high-risk supply-chain actions: it can clone arbitrary git repositories and run pip installs based on install.yaml, and it can execute arbitrary Python code from manifest['verify']['script'] via `python -c`. There are no direct signs of covert malware (no obfuscation or hardcoded exfiltration), but the execution model makes it a likely target/vehicle for supply-chain sabotage if the manifest or referenced dependencies are attacker-controlled. Overall: medium-to-high security risk due to arbitrary code execution and untrusted dependency installation.

Confidence: 72%Severity: 70%
Audit Metadata
Analyzed At
Sep 5, 2026, 08:53 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fwindows-qa-engineer%2F@77703ad3a91ad17e4ad2473e5c09cc392180651f45ff0feea53ed6d400acec84
Security Audit — socket — windows-qa-engineer