qa-changes

Warn

Audited by Socket on May 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose is coherent for QA, but the operational footprint is high-risk: it has the agent read untrusted PR content, execute repo-defined setup commands, run the changed code, interact with services, and autonomously post a GitHub review. This is better classified as suspicious/high-risk QA automation than malicious intent.

Confidence: 89%Severity: 78%
Audit Metadata
Analyzed At
May 8, 2026, 04:32 AM
Package URL
pkg:socket/skills-sh/openhands%2Fskills%2Fqa-changes%2F@350f5d613a6d9d05ab6a4fc0adfaf9a62249e21e