unit-testing-test-generate

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherent with its stated purpose of generating unit tests across languages and frameworks. The internal workflow—code analysis, test generation, mock creation, and optional coverage analysis—fits the goal of maintainable test suites. However, there is a potential command injection risk if user-supplied input is used to form the test_command for coverage analysis. This is the primary security concern. Absent secure validation, the footprint remains benign overall, with MEDIUM risk due to the injection vector. No evidence of credential handling, data exfiltration, or malicious third-party behavior was found.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:52 AM
Package URL
pkg:socket/skills-sh/SivaG-lab%2Froth_mcp%2Funit-testing-test-generate%2F@027f480aa2097b744ea360cb4ae6ab25d3fd90ce