secure-ship

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but it is high-risk because it enables autonomous offensive testing and code-shipping actions, delegates to unseen local skills, and writes telemetry under ~/.claude/projects without explicit user confirmation. This looks more like a powerful vulnerable orchestration skill than confirmed malware.

Confidence: 87%Severity: 83%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fsecure-ship%2F@9bbef25ded97b4e3d9bc68e1836c9b3f2a8099e2
Security Audit — socket — secure-ship