commit

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Commit Skill is coherent with its stated purpose: it analyzes local changes, organizes them into atomic commits with meaningful messages, and provides optional verification, dry-run, amend, and push capabilities using standard Git tooling. There are no external downloads, unverifiable binaries, credential exposure, or data exfiltration patterns. The autonomy provided by verification and push flags is a normal feature for developer tooling, and does not indicate malicious intent. Overall: BENIGN with low-to-moderate security risk due to potential autonomous actions in automated environments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:31 AM
Package URL
pkg:socket/skills-sh/johnie%2Fskills%2Fcommit%2F@1523e82ff83395d6b3d49dacc23caef1229fcc94