release-skills

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The release-skills tool is coherent with its stated purpose as a universal release workflow. It relies on conventional, well-known developer tooling (git, package managers, possibly GitHub CLI) and operates on local files to generate and apply version changes and multilingual changelogs. There are no evident credential reads, no untrusted binary downloads, and no autonomous actions beyond what the user explicitly confirms. The footprint is proportionate to its stated goal and does not exhibit clear malicious data flows or supply-chain risks. Overall, the skill is BENIGN with minor elevated risk due to reliance on external CLI tooling (gh) and multi-language output handling, which is normal for a release automation tool.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:52 AM
Package URL
pkg:socket/skills-sh/ideacco%2Fbaoyu-skills-openclaw%2Frelease-skills%2F@23c3875d98322e278397101a6e1cbf514ae6f43c