Ae1
- Category
- analysis-evasion
- Confidence
- 100% confidence
- Finding
Referenced artifact was not completely inspected
- Content
md Use this portable `SKILL.md` with coding agents that support the Agent Skills format.
Security audit
Security checks for vulnerabilities and agentic risk
GitX is a clearly disclosed Git workflow helper whose repository and GitHub actions match its stated purpose.
Install this only if you want an agent to help operate Git and GitHub in your repositories. Review commands before using workflows that commit, push, create PRs or issues, or resolve conflicts, and treat secret-scan results as sensitive even though the skill instructs redaction.
Referenced artifact was not completely inspected
Use this portable `SKILL.md` with coding agents that support the Agent Skills format.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
For `gitx scan`:
1. Perform a read-only scan of non-ignored working-tree files, staged content, commits reachable from `HEAD`, and locally available `origin/*` history. Do not fetch automatically; state that pushed-history results reflect the locally available remote-tracking refs.
2. Prefer an installed secret scanner such as Gitleaks or TruffleHog without installing tools or uploading repository content. When none is available, inspect filenames and content for likely API keys, access tokens, passwords, connection strings, private keys, credentials, tracked `.env` files, and other sensitive configuration. Distinguish real credentials from obvious placeholders and examples.
3. Classify each finding as `UNCOMMITTED`, `STAGED`, `COMMITTED LOCALLY`, or `PUSHED TO ORIGIN`. Use `PUSHED TO ORIGIN` only when the containing commit is reachable from a locally available `origin/*` ref.
4. Report the severity, exposure class, credential type, file path, line or commit when available, and a recommended action. Redact every value; never print a complete credential or secret.
5. For a pushed credential, say to revoke or rotate it immediately and explain that deleting the file or making another commit does not invalidate the credential. Discuss history rewriting only when the user explicitly asks for remediation.
The default prompt uses a broad, natural-language invocation phrase ('Use $gitx to commit my changes intelligently and safely') that could match ordinary user requests about committing changes. This can cause the skill to activate in situations the user did not explicitly intend, giving a Git-capable skill access to repository operations and related workflows more often than necessary.
No suspicious patterns detected.