privacy-publish
Warn
Audited by Socket on Aug 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent, and the Apple/WordPress endpoint usage is proportionate, but the skill materially depends on an unverifiable local asc.py helper and potentially forwards sensitive publishing credentials through unspecified local tooling. The data flows mostly match the purpose, so this is not clearly malicious, but the install/execution trust boundary is too weak to treat as benign.
Confidence: 82%Severity: 76%
Audit Metadata