qa

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core QA/browser-testing and bug-fix behavior is legitimate, but this skill is overgrown: it includes platform management, telemetry, artifact sync, test/CI bootstrap, CLAUDE.md routing injection, and following other skills. Those extra capabilities are disproportionate to a QA skill and increase trust and data-flow risk, though the content is not clearly malicious.

Confidence: 80%Severity: 68%
Audit Metadata
Analyzed At
May 16, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fqa%2F@a417fdaa6a9608cb78c0fbb9472610e88b3878d6
Security Audit — socket — qa