git-commit

Fail

Audited by Socket on Feb 19, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The described skill implements locally useful git commit automation (granular commits, Conventional Commits, language detection) and does not contain explicit network-based exfiltration or encoded payloads. However, it prescribes highly autonomous behavior: mandatory automatic application, enforced GPG signing, and abort-on-error semantics. Those policy choices create significant operational and security risks (unauthorized persistent changes, accidental committing of secrets, non-repudiable signed commits, and potential workflow deadlocks). Treat this artifact as operationally hazardous unless constrained by explicit user consent, secrets scanning, branch protections, and safer error-handling policies.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 19, 2026, 08:07 AM
Package URL
pkg:socket/skills-sh/totto2727-dotfiles%2Fagents%2Fgit-commit%2F@bacedaba05b7916e64662a62271a00a5a3372538