release-skills
Warn
Audited by Socket on Mar 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The release-skills description is a coherent, multi-language release automation workflow that aligns with its stated purpose of auto-detecting project configuration, determining version bumps, generating multi-language changelogs, and performing release commits/tags with optional pushes. No evidence of malware or covert data exfiltration is present within the fragment. However, the described workflow relies on external tooling (gh CLI and git) and depends on proper authentication and access controls. To mitigate risk, ensure secure handling of credentials (token scopes, least privilege), explicit user confirmation for pushes, and robust access controls in CI environments.
Confidence: 75%Severity: 75%
Audit Metadata