lx-git

Warn

Audited by Socket on May 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated Git-like knowledge-base workflow is internally coherent, and there is no direct malicious code, hidden execution, or obvious credential theft in the skill text. The main issue is trust: it requires a preinstalled, already-authenticated `lx` binary whose publisher and official distribution cannot be verified from the skill, while granting that binary access to local content and remote write operations. This is disproportionate uncertainty for a skill that can push and revert remote data.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 20, 2026, 09:43 PM
Package URL
pkg:socket/skills-sh/tencent-lexiang%2Flexiang-cli%2Flx-git%2F@5f9e3e3b619eb721256f5f2a869db3d74f3dfef9
Security Audit — socket — lx-git