auto-qa

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose broadly matches QA automation, but its operational footprint is unusually expansive. The main risk is not overt malware; it is high-impact autonomous behavior: executing untrusted project code, coordinating many workers, using live credentials/providers, and potentially merging changes into a real repository. No clear credential-harvesting or attacker exfiltration endpoint is present, so this is better classified as a high-risk autonomous/devops skill rather than malicious code.

Confidence: 87%Severity: 79%
Audit Metadata
Analyzed At
Jul 31, 2026, 07:17 PM
Package URL
pkg:socket/skills-sh/steipete%2Fclawdis%2Fauto-qa%2F@9f49b6db07eff80585d7c8d87572084f7b0d10cbd7607e30e43d708721f7d952
Security Audit — socket — auto-qa