gitwhy-context-saving

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s high-level purpose is coherent, but its actual trust model is under-specified: it relies on an unverifiable `git why` toolchain and routes potentially sensitive development context to unnamed external services. The main issue is not obvious malware behavior, but unclear installer provenance and opaque cloud data flows for private engineering reasoning.

Confidence: 86%Severity: 78%
Audit Metadata
Analyzed At
Mar 30, 2026, 12:42 AM
Package URL
pkg:socket/skills-sh/gitwhy-cli%2Fgitwhy%2Fgitwhy-context-saving%2F@1339c4e6d383da7705ba871b36741d19b229172f