qe-stream-chain
Warn
Audited by Socket on Sep 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the documented purpose is coherent, but the skill delegates its core behavior to an ambiguously sourced `claude-flow` CLI with fragmented provenance, unpinned installation paths, and documented credential forwarding/persistence. The markdown itself is not overtly malicious, yet the external dependency trust and data-flow uncertainty are disproportionate enough to treat the skill as medium-high risk.
Confidence: 85%Severity: 78%
Audit Metadata