ship

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS rather than malicious. The core release capabilities match the stated purpose, but the skill performs autonomous repository actions and relies on a third-party AI review CLI that may send code externally. Official GitHub CLI usage is consistent; the main risk is external review/data flow and action-taking without explicit per-step approval.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 5, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fship%2F@1fc8648b8c86dc0b5b26b70327a1b250f5626aaa
Security Audit — socket — ship