claude-code-plugin-release
Warn
Audited by Socket on May 7, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core release automation purpose mostly matches its git/npm/GitHub actions, but it also authorizes autonomous public publishing and a Discord notification driven by secrets from an external local script path. Official CLIs keep supply-chain risk moderate, yet the optional `np` path forwards release credentials to third-party code and the workflow’s real-world actions warrant high operational caution.
Confidence: 87%Severity: 74%
Audit Metadata