publish

Warn

Audited by Socket on Jun 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN but high-risk operational skill. Its capabilities are broadly aligned with release management, and it uses mainly official tooling, but it grants an AI agent substantial autonomous authority to trigger releases, edit public release notes, and post announcements. The main risk is real-world action automation, not hidden malware or deceptive data exfiltration.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Jun 5, 2026, 11:06 AM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-opencode%2Fpublish%2F@ff531c969157d3f691bc5c8336b1e7c95eb6e3a9
Security Audit — socket — publish