commit

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent, but it relies on a nonstandard `git-agent` binary whose provenance and network/data-handling are not well verified from the provided evidence. No clear credential theft or overtly malicious behavior is present, yet the required opaque CLI and possible remote processing make the overall security risk high enough to treat cautiously.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
May 11, 2026, 07:56 AM
Package URL
pkg:socket/skills-sh/FradSer%2Fdotclaude%2Fcommit%2F@73fc158c7ee28ac83958b44d6d93c10100b81f06
Security Audit — socket — commit