ship
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The skill’s actions are broadly aligned with a release/ship workflow and use standard Git/GitHub tooling, but it grants the agent high autonomy to modify code, commit, push, and open a PR without per-action user approval. That makes it suspicious from an operational-risk perspective rather than malware: coherent purpose, but overly autonomous and externally effectful.
Confidence: 91%Severity: 72%
Audit Metadata