git-commits

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s main purpose is not standard git hygiene but concealment: it explicitly removes Claude attribution so commits look user-authored. It also routes commits through an unseen `/commit` skill and local script, expanding trust without transparency. No clear credential theft or exfiltration is shown, so this is not confirmed malware, but it is a deceptive and moderately risky workflow.

Confidence: 90%Severity: 62%
Audit Metadata
Analyzed At
Mar 23, 2026, 09:05 AM
Package URL
pkg:socket/skills-sh/vibeeval%2Fvibecosystem%2Fgit-commits%2F@06ccd85789541d413ca2bcb50a269f54c7319255
Security Audit — socket — git-commits