git-master

Warn

Audited by Socket on Mar 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The 'git-master' skill is a comprehensive, high-power automation guide for git workflows. It does not contain direct exfiltration, remote download-execute chains, or credential harvesting, so it does not look like conventional malware. However, it prescribes and enables high-risk, destructive git operations (automated interactive rebase, resets, force-pushes, worktree removal) and enforces rigid commit-splitting policies that could cause an agent to repeatedly rewrite history and potentially lose or overwrite commits if executed without explicit human oversight. Treat this skill as operationally high-risk: require user confirmation before any destructive command, create backups/recovery branches automatically, and avoid granting autonomous push permissions.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Mar 3, 2026, 03:53 PM
Package URL
pkg:socket/skills-sh/yunseo-kim%2Fawesome-agent-toolbox%2Fgit-master%2F@5e4ab2477def3fb1dc7c0581f0adfbfe8a98c9e9