sync-repos

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly match its purpose and data flow is local, but the trust model is weaker than ideal because it is installed as a third-party skill from a personal GitHub repo and then executes/generated local shell scripts that can rewrite or delete repository files. No credential harvesting or off-platform exfiltration is evident, so this is better classified as medium security risk rather than malware.

Confidence: 89%Severity: 62%
Audit Metadata
Analyzed At
Apr 8, 2026, 07:02 PM
Package URL
pkg:socket/skills-sh/thatrebeccarae%2Fclaude-marketing%2Fsync-repos%2F@b9000b7df749e31ab4efb055a592171436dcd55c