community-publish

Warn

Audited by Socket on May 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capabilities mostly match the stated community-sharing purpose, but the skill performs real-world public publishing actions and routes code publication through a gateway service whose public ownership/provenance is less clear than the branded domain. This is not confirmed malware, but it carries meaningful security risk from outbound code transfer, public posting, and ingestion of third-party community project content.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
May 20, 2026, 12:29 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fcommunity-publish%2F@480a0727ed6f9121eeaa00564746beca62408697