dotfiles-sync

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's footprint mostly matches a legitimate dotfiles-sync workflow, but it has meaningful security risk because it reads broad home-directory state, can execute chezmoi side-effect scripts, and can push sensitive local config upstream. No clear malicious data exfiltration or deceptive third-party routing is present, but the immediate Phase 1 `dotfiles sync` and forced apply/commit/push behavior make it a medium-risk automation skill.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Jul 16, 2026, 04:49 PM
Package URL
pkg:socket/skills-sh/lev-os%2Fagents%2Fdotfiles-sync%2F@1e4dd7be916d1caf3b57a8dd21ed8733767098f5047069c11d2937bfb7baac91
Security Audit — socket — dotfiles-sync