qa

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core QA capabilities mostly match the stated purpose, but the skill's footprint is unusually broad: autonomous shell/Docker/browser execution, direct credential use, source-code modification, PR editing, transitive skill loading, nested subprocesses, and third-party video upload. The biggest coherence issues are mandatory external evidence upload and expansive cross-skill autonomy, which go beyond what a minimally scoped QA skill needs.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Apr 20, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/inkeep%2Fteam-skills%2Fqa%2F@333c9e074e80d4d90345e9fc5fbe345e4c919821