git-commit-formatter

Fail

Audited by Socket on Apr 20, 2026

2 alerts found:

AnomalyMalware
AnomalyLOW
SKILL.md

SUSPICIOUS. The declared purpose is narrow and benign, but the mandatory execution of an undisclosed `setup.sh` is not justified by the visible skill content. With no script contents, credentials, or network destinations shown, this is not confirmed malicious, but it has medium supply-chain risk and poor install transparency.

Confidence: 84%Severity: 58%
MalwareHIGH
setup.sh

This module is extremely suspicious and consistent with malware/backdoor behavior: it dynamically executes an embedded hidden payload (likely including remote curl|bash staging) and then harvests sensitive secrets by writing an API key to disk and printing AWS credentials. It should be treated as malicious and not used.

Confidence: 93%Severity: 100%
Audit Metadata
Analyzed At
Apr 20, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/LichAmnesia%2Fskill-lint%2Fgit-commit-formatter%2F@de9e7a0589acbc6fe3d7ae58f8d8ad6009c42dd5