grond
Warn
Audited by Socket on Aug 30, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
BENIGN overall for a Git push skill: capabilities and data flows match its stated purpose, with no suspicious installer or third-party credential routing. The main risk is high autonomy: it suppresses confirmation and can directly commit/merge/push to the default branch on a one-word trigger, so operational risk is high even though malicious intent is not evident.
Confidence: 93%Severity: 74%
Audit Metadata