git-ship
Warn
Audited by Socket on Mar 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a GitHub automation workflow, and its visible network/data flow stays on official GitHub tooling. However, its core purpose is to bypass CI and branch-review protections using admin privileges, which is disproportionate and high impact for an agent skill; unspecified transitive skills add further trust uncertainty.
Confidence: 94%Severity: 89%
Audit Metadata