git-commit
Audited by Socket on Feb 19, 2026
1 alert found:
Obfuscated FileThe described skill implements locally useful git commit automation (granular commits, Conventional Commits, language detection) and does not contain explicit network-based exfiltration or encoded payloads. However, it prescribes highly autonomous behavior: mandatory automatic application, enforced GPG signing, and abort-on-error semantics. Those policy choices create significant operational and security risks (unauthorized persistent changes, accidental committing of secrets, non-repudiable signed commits, and potential workflow deadlocks). Treat this artifact as operationally hazardous unless constrained by explicit user consent, secrets scanning, branch protections, and safer error-handling policies.