collab

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill's footprint is coherent with its stated purpose of managing collaboration state via Git branches for Claude sessions. The primary interactions are local repository operations and remote pushes governed by a two-stage flow with validation. While there are external integrations mentioned, they appear to be optional enhancements rather than core data exfiltration vectors. The main security considerations are proper access controls, secure handling of remotes, and ensuring that publish/promote operations cannot be abused to push unintended changes. Given the described safeguards (confirmations, --force-with-lease, remote push behavior, and non-persistent local master state), the risk is moderate but acceptable for a collaboration-focused tool when used with proper permissions.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 03:40 AM
Package URL
pkg:socket/skills-sh/teslasoft-de%2Fclaude-skills-marketplace%2Fcollab%2F@d823a91c0edadd345e1284fd0c7f821fb7cbdd1e