whats-new

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill's purpose is coherent: it intends to provide a structured, feature-focused changelog briefing for Claude Code by retrieving the official changelog and rendering per-feature articles via parallel agents. The architecture relies on external fetches and multi-agent orchestration, which is appropriate for the stated purpose but introduces supply-chain and execution risks (dependency on external content, potential rate limits, and complex parallelization). There are no explicit credential exposures or exfiltration patterns, but the approach involves network calls and local cache writes, which should be executed with proper error handling and security considerations. Overall, the code fragment is functionally aligned with its stated goal, but the multi-step, cross-service workflow warrants cautious operational controls and robust failure modes to avoid data leakage, runaway resource usage, or inconsistent outputs.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 11:08 PM
Package URL
pkg:socket/skills-sh/dhughes%2Fclaude-marketplace%2Fwhats-new%2F@99f75b17d3844901473a50ad65230c88e997ecb6