git-commit

Warn

Audited by Socket on Mar 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core repo review and commit behavior is coherent, but the skill is over-scoped for a 'git-commit' helper because it also reads home-directory config, appends to a cross-project history log, and can trigger remote deployment through shell/SSH/SSM commands. Data flows go to official services rather than third-party gateways, so this is not strong evidence of malware, but it carries meaningful operational risk from autonomous push/PR/deploy actions and command execution sourced from local config.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
Mar 30, 2026, 01:12 AM
Package URL
pkg:socket/skills-sh/tsaol%2Fawesome-claude%2Fgit-commit%2F@3ac1f74a110c3e8aadb1698e6d4adedc4c269f98