sync-dotfiles

Warn

Audited by Socket on May 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core local dotfile sync behavior fits the stated purpose, but the skill has two notable risks: an unverifiable fallback clone of `camacho/ai-env` from GitHub and a `skills-push` feature that installs additional skills transitively. No clear credential harvesting or exfiltration is shown, so this is not confirmed malware, but it carries meaningful supply-chain and agent-trust risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 3, 2026, 08:01 AM
Package URL
pkg:socket/skills-sh/camacho%2Fai-skills%2Fsync-dotfiles%2F@449a2c9320c1feb8d13d7fc75b08eb4272d48a7c
Security Audit — socket — sync-dotfiles