ship

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent, but it grants an AI agent unusually broad autonomous control over a development workflow, including automatic commits and optional remote push/PR actions, while also chaining into other skills and external review services. The main risk is autonomy and trust expansion rather than clear malicious behavior.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 5, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/rhuss%2Fcc-spex%2Fship%2F@c0b76d01e734adb23fc477fcca9904b8df2411ea