sync-ag-shared

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose matches its git/GitHub capabilities, but it grants a broad automation footprint across multiple repos, including pushes and PR creation, and delegates edits to sub-agents that process untrusted repo content. Tooling is mostly legitimate, yet the third-party git-subrepo dependency and autonomous multi-repo actions make this medium-to-high risk rather than benign.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/ag-grid%2Fag-charts%2Fsync-ag-shared%2F@8c186e46f2fee78148f8a07e406b6a9864579443