use-git-agent

Warn

Audited by Socket on Mar 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is plausible, but the skill auto-executes an unverifiable `git-agent` CLI, forwards repo content and possibly API keys through that tool, and performs commits without explicit confirmation. The main issue is trust and data-flow opacity, not confirmed malware.

Confidence: 85%Severity: 82%
Audit Metadata
Analyzed At
Mar 24, 2026, 09:43 PM
Package URL
pkg:socket/skills-sh/GitAgentHQ%2Fgit-agent-cli%2Fuse-git-agent%2F@7e7970394dfd6d837a8c8b45901b95cc866988bb