xerahs-release-bump-tag

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is broadly coherent with its stated purpose: it automates a multi-step release process within a Git repository and GitHub-Hosted CI, using standard developer tools and internal scripts. There are no obvious red flags for unverifiable binaries, credential harvesting, or exfiltration to unknown endpoints. The main risks concern credential handling (GH tokens, git credentials) and the potential for automated pushes if misconfigured, so proper access controls and review gates should be in place. Overall, the skill is BENIGN with MEDIUM risk considerations due to credential handling and complex automation; it should be used with explicit guardrails and documentation on credentials provenance.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 06:24 PM
Package URL
pkg:socket/skills-sh/sharex%2Fxerahs%2Fxerahs-release-bump-tag%2F@46d92029013eba1b326a54fc65f7f8d42b34f4c6