skills/socai-io/socai/socai-release/Gen Agent Trust Hub

socai-release

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the official GitHub CLI (gh) to trigger and monitor CI/CD workflows. All commands are scoped to the project's own repository (socai-io/socai) and are used for intended release management tasks.
  • [EXTERNAL_DOWNLOADS]: The skill performs status checks on project-owned domains (socai.io, socai-download.oss-cn-beijing.aliyuncs.com) using curl. These operations are used for verifying that production assets were correctly promoted to mirrors after a successful build.
  • [REMOTE_CODE_EXECUTION]: The skill triggers remote execution via GitHub Actions workflows (release.yml). This is the primary purpose of the skill and occurs within the project's managed CI environment.
  • [SAFE]: Preflight checks and local version calculations utilize Python and Shell scripts. These scripts operate on local repository metadata (tauri.conf.json, git tags) and do not perform network exfiltration or access sensitive system files.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 03:24 AM
Security Audit — agent-trust-hub — socai-release