changelog-auto

Warn

Audited by Socket on Feb 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected This skill contains bash scripts that implement changelog generation from git commit history and optional release integration. The capabilities, file accesses, and actions align with the declared purpose. There are no signs of credential harvesting, external data exfiltration, remote downloads, obfuscation, or other malicious behavior in the provided code. Operational cautions: running scripts that auto-commit and tag should be done with repository access awareness; the placeholder invocation /changelog-auto should be validated in the runtime environment to ensure it runs the expected binary/script. Overall the code appears benign but with moderate operational risk if run in untrusted environments.

Confidence: 88%Severity: 75%
Audit Metadata
Analyzed At
Feb 21, 2026, 12:25 PM
Package URL
pkg:socket/skills-sh/manastalukdar%2Fclaude-devstudio%2Fchangelog-auto%2F@56afcec0b3ac7a480b26725b575fada7a646ff96