semantic-model-deployer

Warn

Audited by Socket on May 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the workflow is largely aligned with its stated Semantius deployment purpose, but it materially depends on an external Semantius CLI and a second skill whose provenance and official documentation are not well established in the evidence. The skill also authorizes high-impact live writes, including cross-module changes and executed seeding scripts, which is proportionate to deployment but risky given the partially unverifiable tool chain.

Confidence: 82%Severity: 76%
Audit Metadata
Analyzed At
May 6, 2026, 05:02 PM
Package URL
pkg:socket/skills-sh/semantius%2Fsemantius-cli%2Fsemantic-model-deployer%2F@adc667adc3cb01481c5aecf02a48b3288606e0b5
Security Audit — socket — semantic-model-deployer