git-commit
Fail
Audited by Socket on Feb 27, 2026
1 alert found:
MalwareMalwareSKILL.md
HIGHMalwareHIGH
SKILL.md
The code fragment describes a Git agent skill focused on safe, conventional-commit-driven commits with explicit human-in-the-loop checks. It aligns with its purpose by enforcing atomic commits, clear messaging in Chinese, and safety reviews. There are no suspicious download/install patterns, credential handling, or network exfiltration behaviors observed. The overall risk is low to moderate due to potential misuse in automation (e.g., bypassing checks if the agent is not properly supervised), but the documented safety steps mitigate this risk. Overall, the material is BENIGN with MEDIUM governance risk due to workflow automation potential.
Confidence: 95%Severity: 90%
Audit Metadata