skill-ship

Warn

Audited by Socket on May 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s overall workflow fits its shipping purpose, but it makes a third-party local orchestrator script mandatory and likely sends project content through multiple external AI providers. This is not fundamentally incompatible with the stated goal, yet the unpinned GitHub-clone execution path and multi-provider data exposure create medium-high security risk.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 9, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/nyldn%2Fclaude-octopus%2Fskill-ship%2F@d528016bddcb696d2c451ecd2cdba3693a946c95