sync-dotfiles

Warn

Audited by Socket on Apr 9, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: local config sync is plausible, but the remote GitHub clone fallback is unverifiable from the evidence and `skills-push` adds transitive `npx`-based skill installation beyond the core purpose. No direct credential theft is shown, but install/execution trust is too weak for a purely benign rating.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 9, 2026, 02:16 PM
Package URL
pkg:socket/skills-sh/camacho%2Fai-skills%2Fsync-dotfiles%2F@b67158104019ad63a03228f2cfb739ee42bb71ce