qa-screenshot-management

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The QA screenshot management skill presents a coherent and proportionate footprint for its stated purpose: organizing, naming, baselining, and documenting QA screenshots. The data flows are primarily local filesystem operations with clear, author-documented conventions. There are no evident credential, network, or executable download patterns that would raise security concerns. While the security risk is low, the absence of explicit install instructions for dependencies (e.g., Playwright) means there is a minor execution-trust gap until those steps are defined. Overall, the skill is BENIGN with a tendency toward cautious security risk due to potential exposure of sensitive test data if images contain secrets and if storage is misconfigured.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/jpoutrin%2Fproduct-forge%2Fqa-screenshot-management%2F@bacfa065639bd5d796bf51fa36395f8b5efc6754