git-auto-commit-push
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core git capabilities match the stated purpose, and there is no external installer or third-party credential proxy. However, the skill is high-impact because it treats loose phrases as authorization for push, requires broad permissions, and explicitly defaults to committing .env files before pushing to whatever remote is configured. That combination is disproportionate for an automation helper and creates meaningful accidental secret-exposure and autonomous-publication risk.
Confidence: 90%Severity: 74%
Audit Metadata