git-workflow

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for git/PR automation, and its data flows mostly match GitHub workflow tasks, but its core reliance on an unverified `gh-tool` and its autonomous handling of untrusted PR comments, code edits, pushes, and public replies increase risk. This looks more like an overpowered workflow skill than confirmed malware, with medium-high security risk driven by execution trust and indirect prompt-injection exposure.

Confidence: 86%Severity: 76%
Audit Metadata
Analyzed At
Apr 23, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/blogic-cz%2Fagent-tools%2Fgit-workflow%2F@694d70e167ce54e9f327481ce2cbd7f5e8fa8d96