quality-assurance

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with its stated QA purpose and does not show direct credential theft, covert behavior, or untrusted installer chains. However, it grants an AI agent security-auditing capability including offensive-capable scanning tools, and some referenced official CLIs may transmit project metadata to vendor services; combined with unspecified local helper scripts, this makes it medium risk rather than benign.

Confidence: 86%Severity: 54%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:13 AM
Package URL
pkg:socket/skills-sh/JochenYang%2FJochen-ai-rules%2Fquality-assurance%2F@2070fc752240b4687cc5b2510d7c394f2021eb16