asc-check-readiness

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent with App Store submission readiness checks, but it relies on a third-party `asc` CLI and includes a risky `eval` pattern that executes command text returned by that tool. Credential use is proportionate to App Store automation, yet trust is delegated to external CLI output and third-party auth handling, making this medium-to-high risk rather than benign.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-check-readiness%2F@e519a8d6e03df164bca4b50c76f191f348bf56c6