chezmoi-workflows

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated purpose (dotfile backup/sync via chezmoi with a GitHub remote) aligns with its capabilities and the described workflow. Access to private repos and usage of git/chezmoi are appropriate for legitimate dotfile management. Security concerns mainly center on credential handling for GitHub/SSH, and the potential for sensitive dotfiles to be transmitted across machines; these are mitigated by private repositories and proper access controls but require explicit user awareness and secure credential management. No evident malicious data exfiltration or unsafe third-party payloads are present, though the gh-based repo creation pathway warrants careful handling of authentication tokens. Overall, the footprint is mostly benign with standard risk expectations for dotfile synchronization tooling.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 07:15 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fchezmoi-workflows%2F@94194818e20ba5169717b4c22d80483cbf4ef300