gwt

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent and the Git/GitHub data flows are proportionate, but the core `gwt` binary is not clearly verifiable from the evidence provided. The skill also increases secret exposure by copying `.env*` files into new worktrees. Main concern is supply-chain trust in the undeclared `gwt` tool, not confirmed malicious behavior.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:11 AM
Package URL
pkg:socket/skills-sh/somtougeh%2Fdotfiles%2Fgwt%2F@52c78c82d509ab619e1d8a035ab7e0c095e307c9
Security Audit — socket — gwt