product-changelog

Warn

Audited by Socket on Mar 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core changelog-writing purpose is plausible, but the skill’s operational footprint is broader than necessary because it requires an external CLI, delegates installation to another skill, grants wildcarded `infsh` shell use, and can fetch arbitrary external pages via a browser app. No confirmed exfiltration or malware is shown, but the trust chain and remote execution model are disproportionate for a documentation-focused skill.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 17, 2026, 11:54 AM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fproduct-changelog%2F@c0f5e533c655b0aaa2a4f5c6484e640243797006