gitwhy-context-saving
Warn
Audited by Socket on Mar 20, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s capabilities broadly match its stated purpose, but it relies on an unidentified GitWhy CLI/MCP service and sends potentially sensitive engineering context to an unnamed cloud backend. The main issue is unverifiable provenance and opaque data routing, not confirmed malicious behavior.
Confidence: 83%Severity: 76%
Audit Metadata