app-store-deployment

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

BENIGN overall, with medium security risk. The skill's capabilities match its stated app-store deployment purpose and mostly use official tooling, but the Android CI example forwards store credentials to a third-party GitHub Action pinned only by mutable tag, which is the main concern.

Confidence: 91%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 11:57 AM
Package URL
pkg:socket/skills-sh/secondsky%2Fclaude-skills%2Fapp-store-deployment%2F@c753116b75ebaa7d54cb2eabf4d74a03b30ef8cd