e2e-testing
Audited by Socket on Feb 17, 2026
1 alert found:
Malware[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] The fragment presents a coherent, benign description of an AI-powered, MCP-integrated testing bridge (flutter-skill) designed for multi-platform UI automation. There are no evident malicious patterns (no hardcoded secrets, no exfiltration hooks) beyond normal operational exposure. Security focus should be on access control to MCP endpoints, proper scoping of bridge permissions, and secure handling of logs and UI data during automated tests. LLM verification: BENIGN: The improved assessment confirms that the skill fragment describes a legitimate multi-platform E2E testing tool with proportional permissions and standard install paths. No runtime secrets, credential capture, or data exfiltration are evident. Scanner anomalies pertain to documentation rather than executable behavior.