asc-cli

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s purpose and requested Apple credentials are broadly consistent with App Store Connect management, but the trust model is weak: it installs a third-party CLI from a Homebrew tap and then forwards Apple API credentials and private key material to it. Without verifiable provenance or source/release evidence, this is best classified as suspicious rather than benign.

Confidence: 80%Severity: 84%
Audit Metadata
Analyzed At
Mar 16, 2026, 09:49 AM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-cli%2F@230560d388ca5abb8f45db7dc3b1deff66cd0616