merge-base-branch
Warn
Audited by Socket on Apr 7, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's core behavior matches its stated git/CI purpose, and there is no clear credential theft or malicious exfiltration path. However, it gives an agent broad autonomous authority to modify git history and execute arbitrary repo-defined npm scripts, so the operational risk is medium even though malicious intent is not evident.
Confidence: 89%Severity: 58%
Audit Metadata