gh-version-control-workflow

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill description presents a coherent, self-contained Git workflow automation framework that uses local scripts to manage worktrees, commits, reviews, and cleanup, with explicit review gating. There are no evident credential harvesting or external data exfiltration patterns, and network activity would be limited to GitHub interactions via git/gh. The footprint is proportionate to the stated purpose, and the risk posture is low-to-moderate (dependent on environment security and proper handling of credentials in the user's setup). Overall, the skill is BENIGN with some SUSPICIOUS-leaning signals only if environment handling deviates from normal secure usage.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 10:51 AM
Package URL
pkg:socket/skills-sh/robertmsale%2F.codex%2Fgh-version-control-workflow%2F@29640aa42627c32cfa82f33daf83a8410f78fb88