skill-article-publisher

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill-article-publisher code/documentation is coherent with its stated purpose of automating MDX validation, semantic commit generation, and git publishing. It relies on local scripts and standard tooling (Python, npm, Git) and does not demonstrate malicious behavior or risky data flows. It should be considered benign with respect to supply-chain security, assuming the referenced scripts themselves are trustworthy and properly audited in the hosting repository. Operational risks to mitigate include ensuring Git credentials are securely managed in CI/CD environments and that validation/build steps are pinned and audited to prevent accidental publishes.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 07:16 PM
Package URL
pkg:socket/skills-sh/foreveryh%2Fclaude-skills-tutorial%2Fskill-article-publisher%2F@a14c24c75b0c30680c69c01bc042cd09b9f23983