qa
Warn
Audited by Socket on Apr 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core QA capabilities mostly match the stated purpose, but the skill's footprint is unusually broad: autonomous shell/Docker/browser execution, direct credential use, source-code modification, PR editing, transitive skill loading, nested subprocesses, and third-party video upload. The biggest coherence issues are mandatory external evidence upload and expansive cross-skill autonomy, which go beyond what a minimally scoped QA skill needs.
Confidence: 87%Severity: 78%
Audit Metadata