code-sync

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core git sync behavior fits the stated purpose, but the skill expands trust by requiring an unreviewed third-party `git-workflow` skill and performs automatic batch push/pull actions across all repos without per-repo confirmation. The main concern is transitive skill installation and broad autonomous repository modification, not overt credential theft or hidden exfiltration.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Mar 18, 2026, 10:34 PM
Package URL
pkg:socket/skills-sh/niracler%2Fskill%2Fcode-sync%2F@63fb080461a98c377b4c61625a4ada42fcaf7604