generate-changelog
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s overall behavior matches its stated changelog/documentation purpose, but it relies on executing an unpinned external CLI (`bunx ghlog`) whose publisher relationship was not verified, and it turns untrusted external patch content into local file edits. That makes it a coherent but medium-risk maintenance skill rather than clearly malicious.
Confidence: 83%Severity: 60%
Audit Metadata