qa-only
What this skill does
QA testing and reporting
github/leoyeai - Command Execution - 2.1k stars
Threat analysis
Skill info
pkg:github/LeoYeAI/openclaw-master-skills@e5199b5?skill=qa-onlyAssessments (3)
Command Execution
Command Execution via local-llm-review
SKILL.md
$_UPD=$(~/.claude/skills/gstack/bin/gstack-update-check 2>/dev/null || .claude/skills/gstack/bin/gstack-update-check 2>/dev/null || true)File System Access
File System Access via local-llm-review
SKILL.md
mkdir -p ~/.gstack/sessions
touch ~/.gstack/sessions/"$PPID"Remote Code Execution
Remote Code Execution via local-llm-review
SKILL.md
3. If `bun` is not installed: `curl -fsSL https://bun.sh/install | bash`Badge
Add the Anomity scan badge for qa-only to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of qa-only? Report an issue or request a rescan.




