commit-and-push

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The workflow is largely coherent for a repo automation skill and uses official Git/GitHub paths, but it enables autonomous remote actions, depends heavily on an unverified repo-local helper script and git hooks, chains into downstream skills, and acts on external review content while retaining write/exec privileges. Not malware, but medium-high operational risk for an AI agent skill.

Confidence: 85%Severity: 64%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:01 PM
Package URL
pkg:socket/skills-sh/a2f0%2Ftearleads%2Fcommit-and-push%2F@28cf12b50a40bbd484d73b47b6d17f47f83b64d8