ios-qa
Warn
Audited by Socket on Jul 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The live-device QA behavior is largely consistent with the stated purpose, but the skill's actual footprint is much broader: it executes many opaque local gstack binaries, can expose remote control over Tailscale, mutates project files and git history, and includes telemetry/artifact-sync features unrelated to immediate QA. With unverifiable required executables and expanded data/control flows, this is high security risk even without clear proof of malware.
Confidence: 83%Severity: 82%
Audit Metadata