sdapp-commit

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is largely coherent with its stated purpose: it commits only explicitly staged changes, enforces guardrails against auto-staging, drafts conventional commit messages, and unconditionally triggers Jira time logging via a separate skill. There are no evident malicious or high-risk behaviors such as reading secret files, exfiltrating data, or downloading binaries. The data flows are contained to local Git state and integration with an authenticated Jira-log workflow. The main consideration is the unconditional Jira logging step, which should be acceptable in a workflow where users anticipate automatic time tracking, but may require explicit user awareness or opt-out options in some environments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 06:42 AM
Package URL
pkg:socket/skills-sh/YTL-Cement%2Fcoding-buddy%2Fsdapp-commit%2F@a02c534b12f334ba68f40c4f35b6bbb76a35d17d