ultraqa

Warn

Audited by Socket on May 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align for an autonomous QA workflow, and there is no clear credential theft or external exfiltration path. However, it enables bounded autonomous code modification/execution and delegates to other internal subagents, so the trust footprint is broader than a simple test runner.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
May 29, 2026, 02:06 AM
Package URL
pkg:socket/skills-sh/yeachan-heo%2Foh-my-claudecode%2Fultraqa%2F@f44e6f971cfa82e09aa25998ff85cacbaff13e14
Security Audit — socket — ultraqa