wjs-publishing-testflight

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

该技能总体与“iOS 自动发布到 TestFlight/App Store”目的高度一致,主要调用官方 fastlane、GitHub Actions 与 Apple 接口,未见明显恶意中转或隐藏外传。风险主要来自高敏感发布凭据集中进入 CI、个人 GitHub 账号托管证书仓库,以及自动提审/推 tag 的真实外部影响;因此更适合判定为 SUSPICIOUS 而非恶意。

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 03:12 PM
Package URL
pkg:socket/skills-sh/jianshuo%2Fclaude-skills%2Fwjs-publishing-testflight%2F@326cf905687f4bfdcb0d82d8af28a5aa3e5060e67c7f31b80180abee954542e0
Security Audit — socket — wjs-publishing-testflight