gwt
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent and the Git/GitHub data flows are proportionate, but the core `gwt` binary is not clearly verifiable from the evidence provided. The skill also increases secret exposure by copying `.env*` files into new worktrees. Main concern is supply-chain trust in the undeclared `gwt` tool, not confirmed malicious behavior.
Confidence: 84%Severity: 72%
Audit Metadata