claude-code-plugin-release

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core release automation purpose mostly matches its git/npm/GitHub actions, but it also authorizes autonomous public publishing and a Discord notification driven by secrets from an external local script path. Official CLIs keep supply-chain risk moderate, yet the optional `np` path forwards release credentials to third-party code and the workflow’s real-world actions warrant high operational caution.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
May 7, 2026, 09:38 PM
Package URL
pkg:socket/skills-sh/thedotmack%2Fclaude-mem%2Fclaude-code-plugin-release%2F@0f59fcfc2de1b1536aa78f99dec166a0b20d79d8
Security Audit — socket — claude-code-plugin-release