doc-changelog
Fail
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The skill is coherently scoped as a changelog generator/maintainer helper. Its stated purpose matches the described capabilities (parsing git history, optionally enriching with GitHub PR data, and formatting Keep a Changelog compliant entries). The data flows are internal to the developer environment (git history, optional gh CLI data) and the sink is the local CHANGELOG.md file in the repository. No external downloads, credential harvesting, or autonomous real-world actions are evident. Overall, the footprint is benign and proportionate to its stated purpose, with only minimal theoretical credential reliance on user-provided tokens for GitHub data enrichment.
Confidence: 98%
Audit Metadata