privacy-publish

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent, and the Apple/WordPress endpoint usage is proportionate, but the skill materially depends on an unverifiable local asc.py helper and potentially forwards sensitive publishing credentials through unspecified local tooling. The data flows mostly match the purpose, so this is not clearly malicious, but the install/execution trust boundary is too weak to treat as benign.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
Aug 2, 2026, 01:30 PM
Package URL
pkg:socket/skills-sh/rshankras%2Fclaude-code-apple-skills%2Fprivacy-publish%2F@a252e383dba03585e7f85ef36ca5ac61feddf33889ec73a17f9f37c7157ee07a
Security Audit — socket — privacy-publish