qa
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core QA/testing behavior broadly matches the stated purpose and uses mostly official local tooling, so this is not clearly malicious. However, the skill is high-impact because it acts fully autonomously, edits code, commits changes, writes to a home-directory memory file, and chains into another skill, making its effective scope broader than a typical QA reviewer.
Confidence: 91%Severity: 74%
Audit Metadata