swain-release
Warn
Audited by Socket on May 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. Most capabilities fit a release-automation skill and there is no evident credential theft or third-party data routing, but the instruction to derive data from the system prompt is a clear misalignment, and the skill executes unspecified repo-local scripts plus processes untrusted repo content while holding write/exec privileges. Overall this looks like a legitimate but risky release skill with one high-severity prompt-boundary issue rather than confirmed malware.
Confidence: 90%Severity: 64%
Audit Metadata