NYC

github-release-swarm

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The release swarm skill fragment is coherent with its stated purpose of orchestrating AI-driven release processes, including changelog generation, versioning, artifact handling, and multi-repo coordination. It relies on common, trusted tooling (GitHub CLI, npm, npx) and an agent-based workflow to manage releases. Data flows align with standard CI/CD patterns, and while there is operational risk from automation breadth, there is no clear evidence of malicious behavior or credential harvesting within the provided content.

Confidence: 65%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/vamseeachanta%2Fworkspace-hub%2Fgithub-release-swarm%2F@81e5a129f672d02b64f84f1e30a45fd9a1c958c0