changelog-gen

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s core behavior is coherent with changelog generation, but it relies on executing a remote npm package and sending local commit history plus an API key through that package to an external AI service. This is better classified as suspicious/medium risk rather than malicious due to supply-chain trust and data exposure concerns, especially without independent verification of the package publisher.

Confidence: 82%Severity: 61%
Audit Metadata
Analyzed At
Mar 24, 2026, 12:27 AM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fchangelog-gen%2F@013072966ae0f14ff1bef9969eed141128364ba8