git-cp

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches Git operations, but the skill enables autonomous public code publication and relies on a transitive git-manager skill installed through a mutable GitHub trust chain. Data flow is mostly coherent with purpose, so this is not confirmed malicious, but it is medium/high risk for unintended disclosure or unsafe delegated execution.

Confidence: 89%Severity: 71%
Audit Metadata
Analyzed At
Mar 21, 2026, 03:51 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fgit-cp%2F@7f1b9c4327c985a9da683d5a6b15c807b74a0901