github

Fail

Audited by Socket on Aug 30, 2026

1 alert found:

Malware
MalwareHIGH
scripts/git-credential-token.py

This module is a high-confidence credential-harvesting utility. It reads a likely secret store (~/.git-credentials or a provided path), parses GitHub HTTPS credential URLs, percent-decodes username/password fields, recognizes GitHub token formats, and immediately prints the recovered token to stdout. Even without visible network exfiltration in this fragment, it directly facilitates theft/disclosure and should be treated as highly unsafe in a software supply chain context.

Confidence: 88%Severity: 90%
Audit Metadata
Analyzed At
Aug 30, 2026, 03:21 PM
Package URL
pkg:socket/skills-sh/nousresearch%2Fhermes-agent%2Fgithub%2F@5c41afd33a41ff30a38c9f6197cf97a4c1021dc7d684c88ab3c30fcd1021121f
Security Audit — socket — github