impact

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The GitNexus impact analysis skill is coherent with its described purpose: it performs local repository analysis to assess blast radius, upstream/downstream dependencies, and test coverage using a CLI. It relies on legitimate tooling patterns (npm/npx or a local binary) and does not request credentials or perform external network actions. The data flow is confined to local repository data and CLI outputs, which is appropriate for the intended developer-use case. Overall security risk is low, with no evident exfiltration or privilege escalation paths. Recommend monitoring for any future introduction of remote calls or credential handling, but as described, it is benign.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 10:35 AM
Package URL
pkg:socket/skills-sh/terrylica%2Fcc-skills%2Fimpact%2F@179baf7e3362c70d211ac269f4b43458d47cf5c0