qa-orchestrator

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent QA orchestration, but it has a broad footprint: reads .env.qa secrets, forwards them to spawned agents, can autonomously create GitHub issues, and can transitively invoke qa-bug-fixer. No clear malicious exfiltration is shown, yet the unspecified install script and optional third-party Forge installer keep trust and data-flow risk at medium.

Confidence: 83%Severity: 61%
Audit Metadata
Analyzed At
May 9, 2026, 08:20 PM
Package URL
pkg:socket/skills-sh/ravnhq%2Fai-toolkit%2Fqa-orchestrator%2F@1438a4a3ea951a866a06b8d414bc6fd59426dc43
Security Audit — socket — qa-orchestrator