grond

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

BENIGN overall for a Git push skill: capabilities and data flows match its stated purpose, with no suspicious installer or third-party credential routing. The main risk is high autonomy: it suppresses confirmation and can directly commit/merge/push to the default branch on a one-word trigger, so operational risk is high even though malicious intent is not evident.

Confidence: 93%Severity: 74%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:30 PM
Package URL
pkg:socket/skills-sh/theorcdev%2Fskills%2Fgrond%2F@9b8d3fd977f072cae58cbc1ebc362b54f2aefdefaa2e70a7aed965c7410e6e2f
Security Audit — socket — grond