content-publish

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is purpose-aligned for content publishing, and data flows mostly stay within Convex and joelclaw.com. The main concern is reliance on a custom `joelclaw` CLI to lease secrets without clear public provenance or release verification; that makes the skill higher-risk than a normal documentation/publishing guide even though there is no strong evidence of credential theft or malicious exfiltration.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Mar 18, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/joelhooks%2Fjoelclaw%2Fcontent-publish%2F@eca1da10701fee197c4dc570235f230156bf8bd0
Security Audit — socket — content-publish