wrap-up
Warn
Audited by Socket on Apr 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core actions largely match a session wrap-up tool, but it grants the agent autonomous commit-and-push authority and local script execution. Main risk is unintended code/data publication to the configured Git remote rather than credential theft or malicious supply-chain behavior.
Confidence: 89%Severity: 72%
Audit Metadata