dotfiles-sync
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's footprint mostly matches a legitimate dotfiles-sync workflow, but it has meaningful security risk because it reads broad home-directory state, can execute chezmoi side-effect scripts, and can push sensitive local config upstream. No clear malicious data exfiltration or deceptive third-party routing is present, but the immediate Phase 1 `dotfiles sync` and forced apply/commit/push behavior make it a medium-risk automation skill.
Confidence: 81%Severity: 58%
Audit Metadata