release-director
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill’s purpose mostly matches its workflow, but it enables real-world release/public-posting actions and relies on unspecified MCP tools with unclear provenance. There is no direct evidence of malware or credential theft, yet the unverifiable tool boundary and upload coordination make it a medium-risk skill that should require explicit user confirmation for each external action.
Confidence: 81%Severity: 58%
Audit Metadata