asc-release-workflow

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow is purpose-aligned for App Store releases, but it routes sensitive release operations through a non-Apple third-party CLI and can execute config-driven pre-archive commands. The capability set is coherent, yet the combination of third-party tool trust, credential use, and autonomous publishing actions makes this a medium-to-high security risk rather than benign.

Confidence: 88%Severity: 69%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:24 AM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-release-workflow%2F@0bd44a6e43d1fd0a56df3f7a5615308a66cca551