github-release-management

Fail

Audited by Socket on Apr 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

SUSPICIOUS: the skill’s capabilities largely match its stated release-management purpose, and most data flows go to official GitHub/npm paths. The main concerns are medium-to-high operational risk from autonomous publishing/deployment actions and the use of third-party `claude-flow`/`@alpha` orchestration in token-rich CI contexts, plus a minor dependency-name mismatch for GitHub MCP integration. This looks more like a high-impact, supply-chain-sensitive automation skill than confirmed malware.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 2, 2026, 07:17 AM
Package URL
pkg:socket/skills-sh/dnyoussef%2Fai-chrome-extension%2Fgithub-release-management%2F@cf0da610a2910778429c7c9e44f9395c572c6151
Security Audit — socket — github-release-management