app-qa-audit

Warn

Audited by Socket on May 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is internally coherent for deep QA, but its footprint is broad and includes offensive-capable reverse engineering, API extraction, trust probing, and live-target automation. There is no clear credential-harvesting or exfiltration path in the skill text, so this is not malware, but it is a high-risk agent capability set that exceeds ordinary QA documentation.

Confidence: 84%Severity: 76%
Audit Metadata
Analyzed At
May 4, 2026, 03:01 PM
Package URL
pkg:socket/skills-sh/kanmi-idris%2Fagent-skills%2Fapp-qa-audit%2F@d93d1f27696e0f0c82d22bdb1a7ed7ada4253e93