autofix-bot-api

Fail

Audited by Socket on Mar 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
scripts/sync_repo.sh

No indicators of malicious code (no obfuscation, no hidden backdoors, no reverse shell). The script's intended purpose—creating and uploading git bundles—is implemented directly and correctly. The principal security concern is the sensitive nature of the data being uploaded: repository contents (which may include secrets) are transmitted to a third-party service using the AUTOFIX_BOT_API_KEY. Ensure the service and API key are trusted, protect environment variables and invocation contexts (avoid running with untrusted arguments), and review repository contents for secrets before using this script in automated contexts.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 16, 2026, 02:42 PM
Package URL
pkg:socket/skills-sh/DeepSourceCorp%2Fskills%2Fautofix-bot-api%2F@31aeb412d14a1a1e9701bcaa0e81e7a4fed14849