stask-qa
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill's stated QA purpose is coherent, and Slack/thread reporting fits the workflow, but its core functionality depends on an unpinned, publicly unverifiable external CLI (`@web42/stask`) executed via `npx`. That creates a disproportionate install/execution trust risk even without clear evidence of malicious intent or credential theft.
Confidence: 81%Severity: 78%
Audit Metadata