dev-ship

Warn

Audited by Socket on May 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior aligns with autonomous GitHub development, and its tools/endpoints are mostly official. The main risk is not credential theft or covert exfiltration, but broad autonomous action plus transitive skill invocation and untrusted issue/review content combined with code execution and GitHub write access.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
May 4, 2026, 04:15 PM
Package URL
pkg:socket/skills-sh/paulund%2Fai%2Fdev-ship%2F@4c77c82f82b87cf21b5e06617a19c38369b55dcb
Security Audit — socket — dev-ship