test-audit
Warn
Audited by Socket on Oct 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose mostly matches the repository-audit behavior, and there is no clear exfiltration or credential harvesting path in the skill text. The main risk is trust: the skill depends on many opaque local gstack executables and eval-based shell integration whose provenance is not established here, giving it a broader and less verifiable execution footprint than a simple test-audit workflow needs.
Confidence: 81%Severity: 72%
Audit Metadata