release
Warn
Audited by Socket on Aug 28, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned and uses mostly normal project/release tooling, but it grants an AI agent authority to carry out public release and distribution actions after a merge using local signing material. That makes it high-impact operational automation rather than malware; the main risk is autonomous real-world publishing, not credential theft or covert exfiltration.
Confidence: 87%Severity: 74%
Audit Metadata