qa-team

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s testing purpose broadly matches command execution and evidence collection, but its footprint is wider than a simple QA helper: it installs a not-clearly-linked external framework, supports remote SSH and shadow workflows, collects rich artifacts, and instructs the agent to load another skill. The main concern is trust and scope expansion rather than confirmed malicious behavior.

Confidence: 79%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 03:28 PM
Package URL
pkg:socket/skills-sh/rysweet%2Famplihack%2Fqa-team%2F@0509ae00461fa41588b1056d27e6e50bb5d93bdc