git-workflow

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: 主体是 benign 的 Git 工作流文档型技能,但内嵌第三方技能安装指令,形成不必要的转移信任链。未见直接恶意代码或凭据窃取,但外部技能来源与后续权限边界披露不足,应按中等风险处理。

Confidence: 90%Severity: 58%
Audit Metadata
Analyzed At
Apr 1, 2026, 03:44 PM
Package URL
pkg:socket/skills-sh/kevinaimonster%2Fskill-hub%2Fgit-workflow%2F@bc318d5084f5644334ab2328a67e089e8d4b5ba2
Security Audit — socket — git-workflow