mobile-ci-cd
Warn
Audited by Socket on Mar 23, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core CI/CD behavior is largely purpose-aligned and uses mostly legitimate tooling, but the skill is overpowered: it runs autonomously, handles high-value signing credentials, pushes artifacts to third-party services, writes telemetry outside the repo, and instructs installation/use of additional deploy skills. This is not confirmed malware, but it carries meaningful operational and supply-chain risk beyond a narrowly scoped configuration helper.
Confidence: 87%Severity: 68%
Audit Metadata