e2e

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core behavior matches an e2e testing agent, but it grants an autonomous agent unusually broad power: install external tooling, run infrastructure, modify application code, commit changes, and write outside the repo. No clear credential-harvesting or malicious exfiltration is present, so this is not confirmed malware; the main concerns are high-impact autonomy, broad execution/write scope, and partially unverifiable install instructions hidden in referenced files.

Confidence: 89%Severity: 76%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fe2e%2F@80ec3d576f178a40e43b336898474c777cdbf137
Security Audit — socket — e2e