qa

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core QA behavior is coherent with its stated purpose, but the skill expands its trust boundary through optional external plugins and transitive skill handoffs with incomplete provenance. Risk is driven more by dependency/credential trust and indirect content handling than by clear malicious behavior.

Confidence: 78%Severity: 57%
Audit Metadata
Analyzed At
Apr 9, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/desplega-ai%2Fai-toolbox%2Fqa%2F@5698df3ba07ba31f19fca5bfd008ffeb6862c90b