mobile-qa

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent with a mobile QA purpose and uses standard official build/tooling paths, but it grants unusually broad autonomy ('test the entire application', no user questions) and includes self-healing code-change loops plus hidden local telemetry writes. No clear credential harvesting, attacker-controlled routing, or malicious install chain is present, so this is not malicious; the main risk is overbroad autonomous scope for a QA skill.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fmobile-qa%2F@4f4797a45fca1d4ffa4882d701ec74581f834966
Security Audit — socket — mobile-qa