qa

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core QA/testing behavior broadly matches the stated purpose and uses mostly official local tooling, so this is not clearly malicious. However, the skill is high-impact because it acts fully autonomously, edits code, commits changes, writes to a home-directory memory file, and chains into another skill, making its effective scope broader than a typical QA reviewer.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:04 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fqa%2F@a5588051052f224d236ac54db1ca8e00138d3f89
Security Audit — socket — qa