codebase-audit-pre-push
Warn
Audited by Socket on Sep 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent for a pre-push audit, but it is broad and powerful. The main risks are repository-wide read/write access, inspection of secret files, and suggested delegation to other community skills. There is no explicit credential exfiltration, remote installer, or attacker-controlled endpoint in the provided skill text, so this is not confirmed malicious.
Confidence: 84%Severity: 59%
Audit Metadata