release-prep

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The release-prep skill is coherently aligned with its stated purpose of automating pre-release tasks and producing a release artifact. Its footprint—local repo inspection, version bump logic, changelog generation, privacy/compliance checks, and metadata validation—matches the described workflow. No external downloads, credential harvesting, or autonomous real-world actions are evident. The few elevated risk signals relate to shell manipulation patterns typical of build tooling; these are mitigated by the constrained, user-in-the-loop nature of the workflow. Overall, the skill is BENIGN with MEDIUM-level security risk due to potential misuse of shell templates if exposed in an unsafe execution environment.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 07:59 PM
Package URL
pkg:socket/skills-sh/Terryc21%2Fxcode-workflow-skills%2Frelease-prep%2F@ac290b2ffcf6d5da61758f695dbc5351e27d7f17