scoutqa-test
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's main purpose and capabilities are mostly coherent, and the CLI install path appears to be official ScoutQA distribution rather than a random payload. Risk comes from routing test instructions, site data, and potentially plaintext credentials to ScoutQA's remote service, plus proactive autonomous test starts and an unpinned global CLI install. This looks like a legitimate hosted QA integration with meaningful security/privacy risk, not confirmed malware.
Confidence: 88%Severity: 58%
Audit Metadata