asc-release-workflow

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow is purpose-aligned for App Store releases, but it routes sensitive release operations through a non-Apple third-party CLI and can execute config-driven pre-archive commands. The capability set is coherent, yet the combination of third-party tool trust, credential use, and autonomous publishing actions makes this a medium-to-high security risk rather than benign.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Apr 1, 2026, 02:29 PM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-release-workflow%2F@122fc9393027d48fea0f08a0fa0999df861191e7