gitsync

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The gitsync skill presents a coherent, purpose-aligned tool for coordinated git synchronization across multiple repos, with reasonable scope and local data flow. It relies on standard git operations and a local project registry, and it includes a structured conflict resolution workflow that involves user input. Security risk is low to medium given local registry usage and absence of external downloads or credential forwarding to unknown services. The main risks concern potential misuses of the local registry (code/path manipulation) and reliance on environment credentials for remote pushes, but these are inherent to any git automation tool. Overall, the footprint is BENIGN with some SUSPICIOUS signals around input handling, but none that indicate malice.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 09:35 AM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fgitsync%2F@98e382315ff373e2bc223b1ad63042bf4c178c54