press
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The documented purpose and visible file/data flows are coherent for a local test-gating skill, and no credential harvesting or external exfiltration is evident. However, the skill's essential behavior is performed by an unseen bundled `press.pyz` executable, so the main trust boundary cannot be verified; that black-box dependency makes the skill high risk even without direct evidence of malware.
Confidence: 86%Severity: 75%
Audit Metadata