omnidist
Warn
Audited by Socket on Mar 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The code fragment describes a coherent, well-scoped skill for bootstrapping omnidist-based release workflows with multi-registry publishing. It uses documented, locally controllable commands (npx invocations) and relies on standard CI secrets for publishing tokens. There are no evident malicious behaviors, no suspicious download patterns, and the data flows align with the stated purpose. The only notable risk is the handling of publishing tokens in CI; ensure secrets are stored securely and access is restricted to the appropriate repository scope.
Confidence: 75%Severity: 75%
Audit Metadata