ship-ticket

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The workflow purpose matches the capabilities, and the referenced skill/install sources appear to be legitimate same-project npm/GitHub documentation rather than obvious malware. Risk comes from transitive skill installation, mutable `@latest` dependency guidance, and autonomous code-host/tracker actions; there is no clear credential theft or malicious exfiltration pattern.

Confidence: 91%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 02:07 PM
Package URL
pkg:socket/skills-sh/travis-south%2Fagsk%2Fship-ticket%2F@9b2f72dddc0ae7f6033d333b49694f7b13cc1ccce13c6c87cb9b87c97385b57b
Security Audit — socket — ship-ticket