asc-release-flow

Warn

Audited by Socket on May 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly align with App Store release management, and requested data is proportionate, but it routes sensitive App Store Connect operations and credentials through a third-party `asc` CLI, including experimental web-session flows. That makes it higher-trust than an Apple-official workflow and introduces medium security risk, though there is no clear evidence of malware or unrelated credential harvesting in the skill itself.

Confidence: 79%Severity: 59%
Audit Metadata
Analyzed At
May 5, 2026, 04:27 AM
Package URL
pkg:socket/skills-sh/rorkai%2Fapp-store-connect-cli-skills%2Fasc-release-flow%2F@12ca23ccbd5ff44abc9fda7f88a485936c548a8d