qe-stream-chain

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the documented purpose is coherent, but the skill delegates its core behavior to an ambiguously sourced `claude-flow` CLI with fragmented provenance, unpinned installation paths, and documented credential forwarding/persistence. The markdown itself is not overtly malicious, yet the external dependency trust and data-flow uncertainty are disproportionate enough to treat the skill as medium-high risk.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Sep 18, 2026, 06:16 PM
Package URL
pkg:socket/skills-sh/proffesor-for-testing%2Fagentic-qe%2Fqe-stream-chain%2F@cada97f9258fa363244a4f3c313d6a2c351da1b0fcb53293246014001cdbd67b
Security Audit — socket — qe-stream-chain