ai-ship

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s capabilities fit its stated purpose, and the referenced core tools appear official, so this is not credential-harvesting malware. However, it grants an AI agent high-impact autonomous software-delivery powers and processes untrusted GitHub/web content while retaining write/exec access, making it a materially risky automation skill.

Confidence: 87%Severity: 73%
Audit Metadata
Analyzed At
Apr 25, 2026, 07:05 AM
Package URL
pkg:socket/skills-sh/paulund%2Fai%2Fai-ship%2F@800279bdf9f8d6b7bbb59e6e6af5a1980ab4081f
Security Audit — socket — ai-ship