Passed all audits
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill enables an AI agent to execute automated workflows consisting of shell commands defined in a repository-local configuration file (.asc/workflow.json). While this is the primary intended functionality for orchestrating App Store Connect tasks, it creates an attack surface for indirect prompt injection if the configuration file is sourced from an untrusted repository.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues