asc-xcode-cloud

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s capabilities largely match its stated Xcode Cloud purpose, but it routes sensitive App Store Connect credentials through a non-Apple third-party CLI and enables real CI actions. The publisher relationship for `asc` appears verifiable and open-source, so this is not confirmed malware, but the install/auth trust and credential-forwarding footprint make it medium risk.

Confidence: 88%Severity: 61%
Audit Metadata
Analyzed At
Mar 14, 2026, 06:23 AM
Package URL
pkg:socket/skills-sh/tddworks%2Fasc-cli-skills%2Fasc-xcode-cloud%2F@963afe3760c12142798fcb0e7a02c9b7cd567d47