visual-testing

Warn

Audited by Socket on May 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated functionality mostly matches visual testing, but it relies on an undocumented external CLI with wildcard execution scope and forwards Figma/AWS credentials through that tool. Without verifiable provenance or endpoint transparency for ironbee-browser-devtools-cli, the dependency and credential-routing footprint is disproportionate to trust.

Confidence: 80%Severity: 83%
Audit Metadata
Analyzed At
May 29, 2026, 01:40 AM
Package URL
pkg:socket/skills-sh/ironbee-ai%2Fironbee-devtools-skills%2Fvisual-testing%2F@252aeabafb2fdbaf169f95601f4cb8b7744cff77
Security Audit — socket — visual-testing