release-director

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose mostly matches its workflow, but it enables real-world release/public-posting actions and relies on unspecified MCP tools with unclear provenance. There is no direct evidence of malware or credential theft, yet the unverifiable tool boundary and upload coordination make it a medium-risk skill that should require explicit user confirmation for each external action.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Mar 27, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/bitwize-music-studio%2Fclaude-ai-music-skills%2Frelease-director%2F@da839764317eac4648284cb58601e891f0b75195
Security Audit — socket — release-director