release-sync

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and file access are coherent, but its trust model is weak because it routes content through external MCP servers that are not fully verifiable from public evidence. This looks more like a legitimate automation with medium supply-chain and data-handling risk than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 15, 2026, 12:24 PM
Package URL
pkg:socket/skills-sh/yonatangross%2Forchestkit%2Frelease-sync%2F@c2503cee398d90f4a69fc92af66155d347e6af5d