ios-qa

Warn

Audited by Socket on Jul 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The live-device QA behavior is largely consistent with the stated purpose, but the skill's actual footprint is much broader: it executes many opaque local gstack binaries, can expose remote control over Tailscale, mutates project files and git history, and includes telemetry/artifact-sync features unrelated to immediate QA. With unverifiable required executables and expanded data/control flows, this is high security risk even without clear proof of malware.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Jul 18, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fios-qa%2F@fb71e540d3784705c21c8de83b9cd5fbfd00b4009912ff6fe30846463be74f20
Security Audit — socket — ios-qa