load-test-scenario-builder

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This code implements load-testing artifacts and is internally consistent with its stated purpose. I found no indicators of malware, credential harvesting, obfuscation, or third-party proxying. The primary security concern is operational: running high-VU/stress or long-duration tests against production or external services without authorization can cause outages or unwanted traffic. Ensure k6 is installed from official sources, run tests only against intended test environments, and avoid embedding real credentials or production endpoints in CI without safeguards.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/patricio0312rev%2Fskills%2Fload-test-scenario-builder%2F@a386ace6c171d05c33141957c3d894063f1203f2