release

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The skill fragment is purpose-aligned for release orchestration, delegating to repo-defined mise tasks and falling back to semantic-release guidance. However, it contains a high-risk download-execute pattern (curl https://mise.run | sh) for error recovery, which constitutes a supply-chain risk if not protected (no integrity verification, no pinning). Credential-related guidance (GH_TOKEN/GH_ACCOUNT in .mise.toml [env]) introduces potential credential exposure to downstream tooling. Overall, the asset shows moderate-to-high risk due to the remote installer pattern and external tooling dependency; treat as SECURITY RISK: MEDIUM-HIGH with recommended mitigations (pin versions, verify checksums, use signed installers, minimize credential exposure, and prefer in-repo or vendor-verified bootstrap methods).

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 27, 2026, 05:30 PM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Frelease%2F@7e1b00fd404909b16394bd15d4b148996b137931