release-manager

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The analyzed code fragment represents a coherent, well-delineated release-management skill intended to automate and govern the morphir-dotnet release lifecycle. Its capabilities are aligned with its stated purpose, it relies on reputable sources (GitHub, NuGet, dotnet tooling), and its data flows are consistent with release orchestration. There are no evident malicious behaviors (no credential harvesting, no hidden network exfiltration, no autonomous real-world actions). The footprint is proportionate to the task, though the high reliance on automation scripts and external services warrants careful access control and monitoring to prevent misconfigurations or unintended public release artifacts. Overall risk is moderate due to complexity and potential for operational mistakes, but not due to malicious intent.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 07:46 PM
Package URL
pkg:socket/skills-sh/finos%2Fmorphir-dotnet%2Frelease-manager%2F@9c4fb4beea64fbfcdd25956cab58eeaf55da8c06