release

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s capabilities largely match its stated release-orchestration purpose, so it is not fundamentally deceptive. However, it grants an AI agent broad release-engineering authority: publishing artifacts, pushing GitHub changes, SSHing into gateways, and posting announcements. Those real-world actions, plus reliance on a third-party Matrix CLI and other skills, make the operational risk medium-high even without clear malware or credential theft behavior.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 07:17 AM
Package URL
pkg:socket/skills-sh/freenet%2Ffreenet-agent-skills%2Frelease%2F@72c352c8f6ede32906270f1f8b343112847985c3