asc-workflow

Warn

Audited by Socket on Mar 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is internally coherent for repo-local release automation, but it grants a workflow engine arbitrary shell execution and can trigger real App Store release actions through an unofficial third-party `asc` CLI. No clear credential theft or exfiltration is shown, so this is not malware; risk is mainly from shell-capable automation plus third-party CLI trust.

Confidence: 87%Severity: 57%
Audit Metadata
Analyzed At
Mar 28, 2026, 06:56 PM
Package URL
pkg:socket/skills-sh/rudrankriyam%2Fapp-store-connect-cli-skills%2Fasc-workflow%2F@4bcebb36b1957d8fefb0332fbb57dcd7bb9825d3