swain-release

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. Most capabilities fit a release-automation skill and there is no evident credential theft or third-party data routing, but the instruction to derive data from the system prompt is a clear misalignment, and the skill executes unspecified repo-local scripts plus processes untrusted repo content while holding write/exec privileges. Overall this looks like a legitimate but risky release skill with one high-severity prompt-boundary issue rather than confirmed malware.

Confidence: 90%Severity: 64%
Audit Metadata
Analyzed At
May 7, 2026, 09:48 PM
Package URL
pkg:socket/skills-sh/cristoslc%2Fswain%2Fswain-release%2F@9d41a47d2159fef6c26c494cace48829e1b8c2b6