commit-message

Warn

Audited by Socket on Mar 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's stated purpose is coherent with its described features, but the installation approach (downloading and executing a script from a remote URL) and plaintext API key storage introduce substantial security risk. The data flow to an external AI provider is expected for functionality but must be carefully secured (least-privilege API keys, minimal data exposure, clear privacy considerations). Overall, the footprint is borderline-suspicious due to supply-chain risk from the install pattern; data flow to OpenAI is standard but requires secure handling of credentials and input data.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 7, 2026, 09:24 PM
Package URL
pkg:socket/skills-sh/appleboy%2Fcodegpt%2Fcommit-message%2F@56a03e9838d1a0b8e62ef6290f2c9a1b899d53ce