qa-team
Warn
Audited by Socket on May 19, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core QA purpose is coherent, but the skill expands trust to ambiguous external skills and MCP tool namespaces without clear provenance or pinning. There is no direct credential theft or obvious exfiltration path in the text, yet the transitive-skill and external-tool trust chain makes the overall execution risk medium-high for an AI agent skill.
Confidence: 86%Severity: 74%
Audit Metadata