gitwhy-context-saving
Warn
Audited by Socket on Mar 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s high-level purpose is coherent, but its actual trust model is under-specified: it relies on an unverifiable `git why` toolchain and routes potentially sensitive development context to unnamed external services. The main issue is not obvious malware behavior, but unclear installer provenance and opaque cloud data flows for private engineering reasoning.
Confidence: 86%Severity: 78%
Audit Metadata