push-pr

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Benign overall. The skill's footprint is coherent with its purpose: it automates standard git/PR workflows without introducing credential harvesting, unverifiable binaries, or broad system access. The primary risks are operational (history rewriting, unintended pushes) rather than security/exfiltration risks. Recommend ensuring safeguards for destructive actions (e.g., prompt confirmations for branch rewrites, clear user prompts for stacked PR decisions) and verifying gh authentication scope to prevent unintended repository access.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:41 PM
Package URL
pkg:socket/skills-sh/gupsammy%2FClaudest%2Fpush-pr%2F@571b0c7d1a5da11211f149a0aa2462d4d847529e