gh-version-control-workflow
Warn
Audited by Socket on May 9, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The stated purpose matches the visible capabilities for a Git/GitHub workflow, and official git/gh usage is proportionate. The main concerns are hidden trust boundaries: unpublished local wrapper scripts, a required dependent skill, and undocumented forwarding to http://host.internal:8765, which makes execution and data flow less verifiable than the skill description suggests.
Confidence: 80%Severity: 56%
Audit Metadata