ship

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s actions are broadly aligned with a release/ship workflow and use standard Git/GitHub tooling, but it grants the agent high autonomy to modify code, commit, push, and open a PR without per-action user approval. That makes it suspicious from an operational-risk perspective rather than malware: coherent purpose, but overly autonomous and externally effectful.

Confidence: 91%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 06:55 AM
Package URL
pkg:socket/skills-sh/topshark-jim%2Fgstack%2Fship%2F@c5b9165e708ad8e2863b7ae9ddab6204f768431a2c3eb535f7dbcb0dce081844
Security Audit — socket — ship