github-release-management

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment presents a feature-rich and coherent release orchestration capability using established tooling. While highly capable, it introduces significant operational risk due to broad automation across multiple repos and external services. There is no evidence of malicious activity within the fragment itself, but strict secret management, per-action approvals, and governance are essential to mitigate potential misconfigurations or abuse in production. Overall assessment leans toward benign with moderate-high security risk due to the automation surface.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/ruvnet%2Fruflo%2Fgithub-release-management%2F@0558d923571cbaaf3f08f68dd987241686180578