capawesome-app-store-publishing

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely purpose-aligned and uses an official same-org npm CLI, so it does not look malicious. However, it has medium risk because it routes highly sensitive Apple/Google publishing credentials through Capawesome’s CLI/cloud and enables consequential app-store publishing actions by the agent.

Confidence: 88%Severity: 58%
Audit Metadata
Analyzed At
Mar 16, 2026, 02:20 PM
Package URL
pkg:socket/skills-sh/capawesome-team%2Fskills%2Fcapawesome-app-store-publishing%2F@77bc4a9830c382302fc9104c2401bdd4bf086d61