gitlawb

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly consistent with its stated decentralized git purpose and routes most data to matching gitlawb infrastructure, but it grants an AI agent high-impact capabilities including repo mutation, PR merge, webhook creation, on-chain registration, and bounty escrow release. The official-looking install paths reduce malware confidence, yet the autonomy and credential sensitivity make the overall security risk high.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Apr 14, 2026, 04:22 PM
Package URL
pkg:socket/skills-sh/enuno%2Fclaude-command-and-control%2Fgitlawb%2F@43157b4ddc625be35a9e3b9246432a9636560170