styleguide

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core file-generation behavior matches the stated purpose, but the skill overreaches by extracting a GitHub token, storing it unencrypted in `~/.git-credentials`, changing global git credential settings, and autonomously pushing to `main`. Data flows go to official GitHub endpoints rather than attacker infrastructure, so this is not confirmed malware, but it is a high-risk, disproportionate credential-handling and autonomous-action design for a style-guide skill.

Confidence: 92%Severity: 86%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:16 AM
Package URL
pkg:socket/skills-sh/ggprompts%2Fhtmlstyleguides%2Fstyleguide%2F@56452d9b47f3ce9455b729e2f8de4ce4364fc154