release-skills

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This Skill description is coherent and aligned with its stated purpose. It performs local repository operations (read version, parse commits, generate changelogs, update version files, commit, tag, push) which are expected for a release automation tool. There are no signs of credential harvesting, external data exfiltration, obfuscated code, or other malicious behaviors in the provided instruction file. The primary security consideration is the high-impact nature of write-and-push operations: the tool must be run with user consent and appropriate CI/credential controls. Use in automated contexts should ensure explicit confirmation and least-privilege credentials for pushes.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/siatwangmin%2Fcoco-skills%2Frelease-skills%2F@0b9cb87228b8bf16f7d3a09cb253f6adc664ff1a