awt

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core capabilities mostly match its stated QA/E2E testing purpose, but it gives the agent broad command execution and code-modification authority through an external CLI, plus optional credentialed AI-provider use with limited transparency about data handling. Main concerns are supply-chain trust in the `aat-devqa` package, autonomous local probing/rebuild behavior, and prompt-injection exposure from untrusted web/app content rather than clear evidence of malware.

Confidence: 76%Severity: 58%
Audit Metadata
Analyzed At
Apr 16, 2026, 02:40 PM
Package URL
pkg:socket/skills-sh/ksgisang%2Fawt-skill%2Fawt%2F@d49591f38dcb3ee98ce77f6de72651523bfcf107
Security Audit — socket — awt