release

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is largely coherent with a release-engineering purpose and uses mostly official GitHub/tooling paths, so it does not look malicious. However, it grants an AI agent broad write/publish abilities across repos and releases, performs package-manager actions, and includes transitive skill use; these make it medium risk even though the data flows are proportionate to the task.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Apr 23, 2026, 01:36 AM
Package URL
pkg:socket/skills-sh/coleam00%2Farchon%2Frelease%2F@c5e0dbb91c575e4b3c6cd7dd39ceb06fd2ce2395