implement-with-remote-feedback

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected BENIGN: The code fragment serves as a structured Git-centric workflow for implementing work with continuous monitoring via remote git logs. It aligns with its stated purpose, has no credential reads, and uses standard Git operations. The main concerns are minor operational quirks (typo in filename, interactive prompts) that could affect automation but do not indicate malicious intent. LLM verification: No evidence of malware or intentionally malicious behavior. The skill is a workflow document that instructs repository-local git operations and pushing to the project's configured remote — behavior consistent with its stated purpose. Primary security concerns are operational: an insistence on pushing every commit increases the risk of accidental credential or secret exposure to the repository remote, and there are small documentation inconsistencies (path mismatch and filename typo) that could l

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/xalior%2Fagent-skills%2Fimplement-with-remote-feedback%2F@6ff844c2baf7fa147cdd81db463324a9fe7fd9a8