forge-ship

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's capabilities mostly match its software-delivery purpose, but risk comes from autonomous unattended actions and the broader transitive trust model for installing a personal-repo skill via the `skills` CLI. No direct credential harvesting, exfiltration endpoint, or off-purpose behavior is visible in this fragment.

Confidence: 81%Severity: 57%
Audit Metadata
Analyzed At
May 5, 2026, 12:06 PM
Package URL
pkg:socket/skills-sh/mgratzer%2Fforge%2Fforge-ship%2F@5c67e6c6b318ad40bd9b86c27a3647b2188a8b86