ship-it

Warn

Audited by Socket on May 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and core capabilities are broadly aligned, but it is a high-impact orchestration skill that autonomously changes code and raises a PR, while delegating critical behavior to unspecified subskills and an unseen local tracker backend. The main concerns are autonomous action, transitive trust, and prompt-injection exposure rather than confirmed malware or direct credential theft.

Confidence: 82%Severity: 68%
Audit Metadata
Analyzed At
May 19, 2026, 02:37 AM
Package URL
pkg:socket/skills-sh/hotpheex%2Fjutsu%2Fship-it%2F@6000725e93fbb248064db4cfb537472d30701dd5
Security Audit — socket — ship-it