codebase-audit-pre-push

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent for a pre-push audit, but it is broad and powerful. The main risks are repository-wide read/write access, inspection of secret files, and suggested delegation to other community skills. There is no explicit credential exfiltration, remote installer, or attacker-controlled endpoint in the provided skill text, so this is not confirmed malicious.

Confidence: 84%Severity: 59%
Audit Metadata
Analyzed At
Sep 1, 2026, 05:15 PM
Package URL
pkg:socket/skills-sh/diegosouzapw%2Fawesome-omni-skills%2Fcodebase-audit-pre-push%2F@0a52b5152ab0cbf43fb10f6f3f2438f75e502e31dba6fcdfab812dba1da21d81
Security Audit — socket — codebase-audit-pre-push