generate-changelog

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall behavior matches its stated changelog/documentation purpose, but it relies on executing an unpinned external CLI (`bunx ghlog`) whose publisher relationship was not verified, and it turns untrusted external patch content into local file edits. That makes it a coherent but medium-risk maintenance skill rather than clearly malicious.

Confidence: 83%Severity: 60%
Audit Metadata
Analyzed At
Apr 7, 2026, 12:37 PM
Package URL
pkg:socket/skills-sh/gramiojs%2Fdocumentation%2Fgenerate-changelog%2F@a0927c646d01a28e961f156d756377eaecb96225