auto-qa
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose broadly matches QA automation, but its operational footprint is unusually expansive. The main risk is not overt malware; it is high-impact autonomous behavior: executing untrusted project code, coordinating many workers, using live credentials/providers, and potentially merging changes into a real repository. No clear credential-harvesting or attacker exfiltration endpoint is present, so this is better classified as a high-risk autonomous/devops skill rather than malicious code.
Confidence: 87%Severity: 79%
Audit Metadata