release-skills

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign. The skill presents a coherent, multi-language release workflow with appropriate scoping to local repository tooling (git, changelog management) and optional GitHub integration for attribution. There are no evident drive-by credential exfiltration or untrusted binary download patterns. The presence of optional CLI usage (gh) for attribution is a normal integration point, provided it runs with user-approved tokens and access scopes. Overall, the footprint aligns with the stated purpose and does not exhibit disproportionate permissions or data flows beyond typical release processes.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/jimliu%2Fbaoyu-skills%2Frelease-skills%2F@e55cefafa07e8e123c7170653f9881018be8d51d