post-merge

Warn

Audited by Socket on Apr 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The overall footprint mostly matches a post-merge deployment skill, and the documented third-party CLIs are legitimate and purpose-aligned. However, the skill reads a raw local secret from `.env`, sources an unseen local `dispatch.sh`, and can execute real deploy commands autonomously, making it medium-high risk even without clear evidence of malicious exfiltration.

Confidence: 86%Severity: 66%
Audit Metadata
Analyzed At
Apr 26, 2026, 07:54 PM
Package URL
pkg:socket/skills-sh/fellowship-dev%2Fdogfooded-skills%2Fpost-merge%2F@e8c254913765aa2a05e7e820da5d0443b969feb8