fix-and-ship
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is purpose-aligned for emergency deployment, but its footprint is high-risk because it empowers the agent to make autonomous production changes, merge/deploy/rollback, and send notifications without explicit approval. Main concerns are autonomy abuse, transitive trust in other skills, and moderate supply-chain risk from runtime npm execution; data flows are mostly proportional and not overtly deceptive.
Confidence: 88%Severity: 89%
Audit Metadata