use-git-agent
Fail
Audited by Snyk on Mar 24, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The skill is high-risk because it is designed to automatically run commits on load and send repository diffs/history (including potentially sensitive code or secrets) to external AI providers — with a fallback that uses build-embedded credentials (--free) and automatic hook/script installation — enabling unintended data exfiltration and persistent local changes without explicit user consent.
Issues (1)
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata