ship

Warn

Audited by Socket on Jun 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill is largely aligned with its stated purpose: it is a release/PR automation workflow using normal git and GitHub CLI operations, with no obvious credential harvesting or suspicious data exfiltration. The main risk is autonomy: once invoked, it can make and publish code changes and create a PR, and it also acts on external review/CI content while retaining write/push capability. Overall this looks coherent but operationally high-impact rather than malicious.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 13, 2026, 05:30 AM
Package URL
pkg:socket/skills-sh/millionco%2Freact-doctor%2Fship%2F@4e7305d270503c3baf78ed0b41c6d108cc4b5bdc3f4d38ff7746a9d8e09ef874
Security Audit — socket — ship