NYC

git-multibranch

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

This is a procedural guide for Git multi-branch deployments using SSH and post-receive hooks. The core capability (bare repo + post-receive checkout to per-branch web dirs) is legitimate and common. However, the document repeatedly recommends insecure practices for convenience: enabling password authentication on SSH, using sshpass with plaintext passwords, bypassing host key checks, and suggesting force-push without adequate warnings. Those practices materially weaken security and could easily lead to credential exposure or MITM attacks if applied in production. I classify the document as suspicious from an operational security standpoint (not overtly malicious), and I recommend treating the guidance as potentially dangerous unless rewritten to use key-based deploy credentials, least-privilege service accounts, and safer host-key/verification practices.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:50 PM
Package URL
pkg:socket/skills-sh/letta-ai%2Fskills%2Fgit-multibranch%2F@8156c00b72e21341072c370eae513f383900d614