git-commit-submit-pr-and-verify

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's described behavior is reasonable for automating commit/PR workflows, but as implemented it requests high privileges (Bash shell access and transitive skill invocation) and lacks scoping for credentials and target repositories. This combination creates realistic supply-chain and credential-exposure risks: the invoked skill or any shell-invoked tooling could read local credentials, exfiltrate code, or perform unwanted merges. Treat this skill as high-risk unless used with strict mitigations (ephemeral scoped credentials, explicit user approvals, sandboxing of shell commands, and vetted transitive skills).

Confidence: 98%
Audit Metadata
Analyzed At
Feb 28, 2026, 10:32 AM
Package URL
pkg:socket/skills-sh/codyswanngt%2Flisa%2Fgit-commit-submit-pr-and-verify%2F@d9ad2508de8f7039b80028edd87f061b3700f627