positron-qa-verify

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill fragment is purpose-aligned and proportionate for its stated goal of generating QA verification guides from GitHub issues/PRs. It relies on standard, trusted tools (GitHub CLI) and writes output to a controlled local path, with non-interactive, parallelizable workflows. No malicious data flows, credential harvesting, or unintended external communications are evident within the provided fragment. Overall security posture is BENIGN with MEDIUM overall risk due to external API interactions (GitHub) and potential misconfigurations in automated workflows, but nothing suggests malicious intent or supply-chain risk in this fragment.

Confidence: 65%Severity: 50%
Audit Metadata
Analyzed At
Feb 26, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/posit-dev%2Fpositron%2Fpositron-qa-verify%2F@2ca69c698a976ab295fd506b716e3f3dfce85d1c