bump-version

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN: The code fragment describes a self-contained, legitimate release automation workflow for version bumps and changelog management. It relies on standard Git operations and file edits, with no credential handling, network exfiltration, or executable downloads. The only notable aspect is an unusually strong, non-functional safety/consistency admonition about preserving changelog history, which is within user guidance for maintaining changelog integrity. Overall, the footprint is coherent with its stated purpose and does not introduce supply-chain security risks.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/jim60105%2Fcopilot-prompt%2Fbump-version%2F@ac9509f8ebac115b8571c069d4f72d096546c2a6