omnidist

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment describes a coherent, well-scoped skill for bootstrapping omnidist-based release workflows with multi-registry publishing. It uses documented, locally controllable commands (npx invocations) and relies on standard CI secrets for publishing tokens. There are no evident malicious behaviors, no suspicious download patterns, and the data flows align with the stated purpose. The only notable risk is the handling of publishing tokens in CI; ensure secrets are stored securely and access is restricted to the appropriate repository scope.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 08:56 AM
Package URL
pkg:socket/skills-sh/metalagman%2Fagent-skills%2Fomnidist%2F@0061be18d4bbee9b015a90cd429de706b1412d76