app-store-publish
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core Fastlane/App Store setup is largely coherent and uses official registries and Apple endpoints, but the skill is over-autonomous for a deployment task with real-world publishing consequences, forwards Apple credentials into a third-party CLI, silently logs telemetry, and nudges follow-on skill chaining. Risk is driven more by autonomy and credential handling than by malware-like behavior.
Confidence: 89%Severity: 64%
Audit Metadata