release-health
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The release-audit purpose is coherent, but the skill relies on an unverified external `gh-manager` binary to perform both analysis and privileged GitHub write/publish actions. Because the likely tool is a personal third-party CLI that would receive GitHub credentials, the supply-chain and credential-forwarding risks are disproportionate unless the publisher can prove an official, versioned, auditable source.
Confidence: 88%Severity: 85%
Audit Metadata