repo-sync-steward

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill description is purpose-aligned and internally coherent: it deploys safe, standard SCM operations to synchronize content across repos with explicit path linters and validations. No suspicious data flows, credential handling, or external network activity is evident. While operationally sensitive (conflict resolution, correct remotes, and path mutations), these are expected in a cross-repo sync workflow and do not indicate malicious behavior or exfiltration. Overall risk is low with respect to security implications, and the behavior is proportionate to the stated purpose.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/frankxai%2Ffrankx.ai-vercel-website%2Frepo-sync-steward%2F@a67191ed175ee9d74728f588d0767dd0c244c305