github-release-management

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

Overall, the fragment presents a coherent, purpose-aligned release automation skill with AI swarm coordination. The data flows, dependencies on official tooling, and use of CI/CD secrets are consistent with its stated objective. Elevated risk stems from the broad automation surface and cross-repo orchestration, which require strict access controls, audit logs, and clear release authorization policies. No evidence of malicious activity (data exfiltration, backdoors, or credential harvesting) is observed in the provided content. The security posture is acceptable for a controlled CI/CD environment, but the integration should enforce least-privilege permissions and protect logs from secret leakage.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 05:45 AM
Package URL
pkg:socket/skills-sh/ruvnet%2Fagentic-flow%2Fgithub-release-management%2F@cf0da610a2910778429c7c9e44f9395c572c6151