awt-e2e-testing
Warn
Audited by Socket on Apr 18, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is coherent for an E2E testing skill, but the main concern is the explicit transitive skill installation from a third-party GitHub repo via `npx skills add`, with no verification details or scoped permission boundaries. The capability set broadly fits testing, yet the install path and potential to process untrusted web content under agent control make this a medium-to-high security risk rather than benign.
Confidence: 83%Severity: 68%
Audit Metadata