build-feature

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The fragment describes a legitimate developer workflow for leveraging ShipSwift recipes to build iOS features, including steps to install tooling, connect to a recipe server, and generate integration code. The only notable security concern in this static description is guidance to store and export an API key (SHIPSWIFT_API_KEY) in shell startup files, which could lead to credential exposure if not properly protected. Otherwise, the footprint aligns with the stated purpose of a code-assist skill that orchestrates recipe retrieval and code generation. Overall risk is moderate due to credential handling guidance, with no explicit executable payloads or autonomous actions beyond code generation guidance.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 26, 2026, 12:28 PM
Package URL
pkg:socket/skills-sh/signerlabs%2Fshipswift-skills%2Fbuild-feature%2F@fe01197fcf88c7c0ecdd76c1fff7c3419ac9dadf