create-release

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is coherently scoped to its stated purpose: generating a changelog from merged PRs and publishing a release on Gitee via MCP, with explicit steps and user confirmations. Security concerns are moderate and mainly revolve around proper authentication/configuration of the MCP endpoints, potential exposure of PR-derived content in the release body, and ensuring only intended releases are created. No explicit credential harvesting or untrusted external downloads are described. Overall, the footprint is proportionate to the release automation task, but ensure MCP credentials are securely managed and consider adding explicit content sanitization for PR titles/descriptions to avoid leaking sensitive information.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 12:06 PM
Package URL
pkg:socket/skills-sh/oschina%2Fgitee-agent-skills%2Fcreate-release%2F@16be02eb98deb87e5c7f2d24e0a09bd304366501