minecraft-ci-release

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill aligns well with its stated purpose: it defines CI/CD pipelines, release automation, and artifact publishing for Minecraft mods across NeoForge/Fabric, Modrinth, CurseForge, and GitHub Releases. The install sources are official registries/plugins, and data flows follow standard CI publishing patterns. Credential usage is limited to CI secrets for publishing, which is appropriate for the workflow. While there are standard security considerations around secret handling in CI (rotation, least privilege, masking), there is no evidence of malicious data exfiltration or untrusted binary execution. Overall, the footprint is coherent and proportionate to the described purpose, with moderate security risk due to typical CI secret handling. Therefore: BENIGN with caveats for secure secret management.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 03:02 PM
Package URL
pkg:socket/skills-sh/Jahrome907%2Fminecraft-codex-skills%2Fminecraft-ci-release%2F@664bb48acbfae10249f77ea7104e2ca0db380497