questlog

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's core purpose is coherent, but it relies on a not-clearly-verifiable npm CLI, reads persisted auth config, uploads local files to a remote server, and performs transitive MCP/skill installation via `ql install`. The data flows are plausible for a task system, yet the install trust and transitive-loading behavior raise medium risk.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Apr 7, 2026, 02:09 PM
Package URL
pkg:socket/skills-sh/passportxyz%2Fquestlog%2Fquestlog%2F@87d6cfa88fc537eb794fdaa6f955abcda4e65eb2