product-changelog

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose is mostly consistent with writing release notes and generating visuals, but the skill is overextended by broad bash access, dependency on an external CLI with imperfect install/provenance clarity, remote URL-processing apps, and transitive skill installation instructions. This looks more like a platform-onboarding skill than a narrowly scoped changelog helper, so risk is medium rather than benign.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
Apr 23, 2026, 10:14 PM
Package URL
pkg:socket/skills-sh/infsh-skills%2Fskills%2Fproduct-changelog%2F@6e85cf484d18ee4764d7e369cb71a07ecefec089