test

Warn

Audited by Socket on Apr 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill is mostly purpose-aligned for test analysis, but it combines local code execution with autonomous GitHub issue creation and possible npx package fetching. Data flows go to official GitHub endpoints, not an obvious exfiltration host, so this is better classified as a high-risk vulnerable skill than malware.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 20, 2026, 05:30 AM
Package URL
pkg:socket/skills-sh/rube-de%2Fcc-skills%2Ftest%2F@73667f65e60d7a943400533dd80df3c2e85399c5