qa-exploring-tester

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's QA purpose is plausible and mostly aligned, with no obvious malicious endpoint or installer, but it expands trust through many unseen subagents, forwards credentials in plaintext across agents, and combines untrusted external content with autonomous testing behavior. Main risk is agentic overreach and prompt-injection exposure rather than confirmed malware.

Confidence: 86%Severity: 61%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:35 PM
Package URL
pkg:socket/skills-sh/wizeline%2Fsdlc-agents%2Fqa-exploring-tester%2F@6c8b7c0c1fee4a8000437c4494e1373c84728f4e
Security Audit — socket — qa-exploring-tester