qa-team

Warn

Audited by Socket on May 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core QA purpose is coherent, but the skill expands trust to ambiguous external skills and MCP tool namespaces without clear provenance or pinning. There is no direct credential theft or obvious exfiltration path in the text, yet the transitive-skill and external-tool trust chain makes the overall execution risk medium-high for an AI agent skill.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
May 19, 2026, 12:57 AM
Package URL
pkg:socket/skills-sh/laststance%2Fskills%2Fqa-team%2F@f0f0f701358176974f89883e8ec320e3c794a16e
Security Audit — socket — qa-team