ship

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's capabilities broadly match its stated release-automation purpose, and there is no evident credential harvesting or third-party interception. However, it grants an AI agent high-impact autonomous publishing powers—push, merge, and release—using Bash and GitHub CLI without explicit per-action approval, making it high operational risk even though it is not malware.

Confidence: 89%Severity: 81%
Audit Metadata
Analyzed At
Mar 27, 2026, 11:27 PM
Package URL
pkg:socket/skills-sh/bitwize-music-studio%2Fclaude-ai-music-skills%2Fship%2F@fd10b1bf9f154604e7a8d00d79d11f4d7733e0b2