app-store-publish

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core Fastlane/App Store setup is largely coherent and uses official registries and Apple endpoints, but the skill is over-autonomous for a deployment task with real-world publishing consequences, forwards Apple credentials into a third-party CLI, silently logs telemetry, and nudges follow-on skill chaining. Risk is driven more by autonomy and credential handling than by malware-like behavior.

Confidence: 89%Severity: 64%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fapp-store-publish%2F@47cfa90883abd858a0f743cf55022264519fa15f
Security Audit — socket — app-store-publish