gh-version-control-workflow

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose matches the visible capabilities for a Git/GitHub workflow, and official git/gh usage is proportionate. The main concerns are hidden trust boundaries: unpublished local wrapper scripts, a required dependent skill, and undocumented forwarding to http://host.internal:8765, which makes execution and data flow less verifiable than the skill description suggests.

Confidence: 80%Severity: 56%
Audit Metadata
Analyzed At
May 9, 2026, 12:27 PM
Package URL
pkg:socket/skills-sh/robertmsale%2F.codex%2Fgh-version-control-workflow%2F@bf97021c68da2adfc21cb6cc7393306b2d87edf7