user-acceptance

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core UAT purpose is coherent, and most requested actions are proportionate to acceptance testing. The main risk is the explicit instruction to install additional skills on demand, creating a transitive trust/supply-chain path that extends beyond simple evidence collection; combined with processing untrusted app content under exec-capable tooling, this makes the skill medium risk rather than benign.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
May 10, 2026, 11:46 PM
Package URL
pkg:socket/skills-sh/gannonh%2Fskills%2Fuser-acceptance%2F@f2db67d6c05893b62fd5553476184d6cc01bf770
Security Audit — socket — user-acceptance