product-changelog

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is mostly consistent with writing release notes and generating visuals, but the skill is overextended by broad bash access, dependency on an external CLI with imperfect install/provenance clarity, remote URL-processing apps, and transitive skill installation instructions. This looks more like a platform-onboarding skill than a narrowly scoped changelog helper, so risk is medium rather than benign.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
May 15, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fproduct-changelog%2F@f23b698056423c6de06332b7dbef1a233ba3b0a4
Security Audit — socket — product-changelog