asc-code-signing

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities align with Apple code-signing management, but it routes sensitive App Store Connect credentials through a third-party CLI and enables high-impact account changes. Because the tool appears same-publisher, source-available, and purpose-consistent, this is not confirmed malware; the main concerns are third-party credential handling, medium supply-chain trust, and autonomous destructive actions if run without explicit approval.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:24 AM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-code-signing%2F@ec72971144f9068587fb58034c6b37e631a65702