clean-branches

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it identifies merged and stale branches, requires explicit user confirmation, and uses safe delete semantics. It minimizes data exposure and avoids autonomous real-world actions or credential usage. The only moderate concern is potential shell-injection risk if the user-supplied pattern isn't sanitized by the underlying script, but this appears to be an edge-case mitigated by internal script handling. Overall, the tool is benign and appropriately scoped for its purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/gupsammy%2FClaudest%2Fclean-branches%2F@ea0bcaaf63c237668389ac1deace8ca6139e9a12