ship

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow largely matches its stated shipping purpose, but it is high-impact: it can autonomously commit, push, create PRs, reply to review systems, log telemetry through opaque helper binaries, and auto-execute another skill. Same-suite provenance reduces malware concern, yet the action scope and transitive trust make the skill high security risk for an agent.

Confidence: 88%Severity: 76%
Audit Metadata
Analyzed At
Jul 15, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/Lua2147%2Fclaude-toolkit-catalog%2Fship%2F@c342c382e83cc89129d1df3821dbb493a2d834deb6f9e1b596ab786d37c1eab6
Security Audit — socket — ship