git-master
Audited by Socket on Mar 3, 2026
1 alert found:
SecurityThe 'git-master' skill is a comprehensive, high-power automation guide for git workflows. It does not contain direct exfiltration, remote download-execute chains, or credential harvesting, so it does not look like conventional malware. However, it prescribes and enables high-risk, destructive git operations (automated interactive rebase, resets, force-pushes, worktree removal) and enforces rigid commit-splitting policies that could cause an agent to repeatedly rewrite history and potentially lose or overwrite commits if executed without explicit human oversight. Treat this skill as operationally high-risk: require user confirmation before any destructive command, create backups/recovery branches automatically, and avoid granting autonomous push permissions.