stask-qa

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's stated QA purpose is coherent, and Slack/thread reporting fits the workflow, but its core functionality depends on an unpinned, publicly unverifiable external CLI (`@web42/stask`) executed via `npx`. That creates a disproportionate install/execution trust risk even without clear evidence of malicious intent or credential theft.

Confidence: 81%Severity: 78%
Audit Metadata
Analyzed At
Apr 11, 2026, 04:16 PM
Package URL
pkg:socket/skills-sh/yarn-rp%2Fstask%2Fstask-qa%2F@d97fbe9efbf4e265376de210be8c7f0cfd1bc66c
Security Audit — socket — stask-qa