ship

Warn

Audited by Socket on Sep 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core git/GitHub workflow fits a shipping skill, but it manually reads a local Forgejo token and sends it to an unspecified API endpoint, which breaks data-flow transparency. Risk is elevated further by direct-to-main, issue-closing, branch-deletion autonomy and delegation to another skill, though there is no evidence of overt malware or a download-execute installer chain.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Sep 2, 2026, 11:46 AM
Package URL
pkg:socket/skills-sh/matteocervelli%2Fllms%2Fship%2F@227e857782989d8ee29c35d922420eab164359f1f5c703da6690d495798f3b53
Security Audit — socket — ship