git-workflows

Fail

Audited by Socket on Mar 2, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The code fragment is a coherent, governance-focused workflow specification for agent-assisted Git workflows. It is internally consistent with its described purpose and does not contain active malware or exfiltration logic. The most notable risk stems from operational procedures (secret rotation, force-push history edits) that could be misused if automated without safeguards. Overall, the content is BENIGN with moderate security risk due to potential policy/ops misuse in automated contexts.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Mar 2, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/fyrsmithlabs%2Fmarketplace%2Fgit-workflows%2F@9c83042e0cf9ca2bb0259d6988620ff286c6dee6