coregit

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core repo-management and API flows are broadly aligned with the stated purpose and point to first-party Coregit domains, but the skill relies on an unpinned runtime `npx` installer (`coregit-wizard@latest`), claims to install another skill, stores credentials opaquely, and exposes remote command execution. Without external evidence tying the wizard package to the same publisher and documenting that install path as official, the install-trust and transitive-trust risks are disproportionate enough to warrant suspicion rather than benign classification.

Confidence: 79%Severity: 67%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:57 PM
Package URL
pkg:socket/skills-sh/Strayl-Inc%2Fskills%2Fcoregit%2F@b8383155f7837d2967a9dfaea16cb68ff8c203e3