git-repo-digest

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/digest.cs

The code appears to be a legitimate deterministic Git repository documentation/evidence generator and contains no direct indicators of malware, credential theft, persistence, sabotage, or data exfiltration. The principal supply-chain risk is the result-validation workflow: untrusted package IDs and authored examples can cause dotnet test to restore and execute arbitrary NuGet packages and build/test code, with wildcard versions further increasing exposure. Network requests to repository-derived documentation URLs also create a constrained but real SSRF/privacy risk. Validation should be performed only in an isolated sandbox with restricted network access, pinned package versions, and trusted workspaces.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Aug 28, 2026, 08:09 PM
Package URL
pkg:socket/skills-sh/codebeltnet%2Fagentic%2Fgit-repo-digest%2F@8ed13017c086d8ed9f258e5941c734156738c3504ce879ea25044e1356a05007
Security Audit — socket — git-repo-digest