team-qa
Warn
Audited by Socket on Sep 30, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the QA workflow is broadly aligned with its stated purpose, and there is no evidence of credential harvesting or external exfiltration. The main risk is the load-time pre-execution of an unverifiable local helper script plus some reduced-transparency behavior ('silently append') and autonomous progression, making this a moderate-risk skill rather than confirmed malware.
Confidence: 90%Severity: 64%
Audit Metadata