release-iterate-changelog

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

No clear malicious code patterns were found in the provided skill text. The primary security concerns are operational: ability to write/commit files and to invoke other plugin commands that may post externally. These behaviors are expected for changelog automation but warrant cautious controls: preserve the human-review HARD STOP, require explicit confirmation before committing or posting, validate persisted paths, and review the implementations of delegated /jaan-to:* commands. If those controls are observed, the tool is acceptable for use; if not, restrict its permissions.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/parhumm%2Fjaan-to%2Frelease-iterate-changelog%2F@fc70a8d44322300162f1efec527baec6bdf026b0