custom-skills-git-commit

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
pr.md

The code describes a legitimate Git-to-Pull-Request automation workflow and contains no clear malware or data-exfiltration behavior. It has moderate security and integrity risk because it may execute an external Markdown-defined analysis step, uses multiple unquoted shell variables, stages all repository changes, and force-pushes after squashing commits. Inputs should be strictly validated and shell arguments quoted; execution of `pr-analyze.md` should be replaced with a constrained, non-executable parsing mechanism.

Confidence: 95%Severity: 62%
Audit Metadata
Analyzed At
Aug 28, 2026, 08:16 AM
Package URL
pkg:socket/skills-sh/valorvie%2Fai-dev-skills%2Fcustom-skills-git-commit%2F@46358af35c91c382e01afdfbd6f244df931cc213bf511fc80801156e8f9d436f
Security Audit — socket — custom-skills-git-commit