validator-commit

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill is purpose-aligned and shows no direct exfiltration or overtly malicious behavior, but it depends on an unverifiable external CLI (`agent-validate`) and delegates to other local skills. That makes it high risk from a trust and provenance standpoint, though better classified as suspicious/vulnerable rather than malicious.

Confidence: 87%Severity: 75%
Audit Metadata
Analyzed At
May 17, 2026, 12:26 AM
Package URL
pkg:socket/skills-sh/Codagent-AI%2Fagent-validator%2Fvalidator-commit%2F@0b52593aec2444869ebb47dd28997c1d9ef03d98
Security Audit — socket — validator-commit