qa-web-test

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated QA purpose is mostly aligned with its capabilities, but the skill relies entirely on a transitive PinchTab skill and can inspect arbitrary web content with Write/Bash access. PinchTab appears legitimate and same-org documented, so this is not strong evidence of malware, but the trust chain and untrusted-page processing make it medium risk rather than benign.

Confidence: 80%Severity: 54%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:45 PM
Package URL
pkg:socket/skills-sh/delexw%2Fclaude-code-misc%2Fqa-web-test%2F@73bf5ff9d4b6a0601d0cf467f472d1a888149ea3