gitbackup-github-desktop

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's core behavior is mostly coherent with a GitHub backup app, and network flows target expected services. The main concern is install trust: ara.so publishes the skill, but users are told to download and run a prebuilt binary from a different GitHub publisher, plus the app handles high-value credentials and briefly embeds the GitHub token into clone URLs. This looks more like a high-risk third-party desktop tool recommendation than overtly malicious behavior.

Confidence: 85%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fgitbackup-github-desktop%2F@4b163adefe93ac12c1361a524ad46131c306e2aa