signal-push

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches Git commit/push automation, and data flow is mostly coherent, but the actual execution relies on unseen local scripts plus an unprovided dependent skill, and the Windows path disables execution-policy protections. Main risk is autonomous pushing to a remote without confirmation and incomplete transparency into the wrapped commit logic, not confirmed malware.

Confidence: 86%Severity: 62%
Audit Metadata
Analyzed At
May 10, 2026, 04:57 PM
Package URL
pkg:socket/skills-sh/mattbaconz%2Fsignal%2Fsignal-push%2F@792af7f4da3cb1fdfbfcf6eceec7d23bb09c4e93