Summary
git-sync v2.26.6 was classified as CRITICAL RISK with a risk score of 381. Sigil detected 31 findings across 35 files, covering phases including code patterns. Review the findings below before installing this package.
Package description: 全平台统一发布工具。支持 skills 和 agents 的 Gitee/GitHub/ClawHub/SkillHub/PyPI 同步与 Release 创建,LLM 驱动的文件过滤与脱敏。
v2.26.6
19 July 2026, 22:13 UTC
by Sigil Bot
Risk Score
381
Findings
31
Files Scanned
35
Provenance
Findings by Phase
Phase Ordering
Phases are ordered by criticality, with the most dangerous at the top. Click any phase header to expand or collapse its findings. Critical phases are expanded by default.
Badge
Markdown
[](https://sigilsec.ai/scans/33974701-0A6C-41E9-A8AB-D1CCCACBC3EA)HTML
<a href="https://sigilsec.ai/scans/33974701-0A6C-41E9-A8AB-D1CCCACBC3EA"><img src="https://sigilsec.ai/badge/clawhub/git-sync" alt="Sigil Scan"></a>Run This Scan Yourself
Scan your own packages
Run Sigil locally to audit any package before it touches your codebase.
Sigil Pro
Cloud scanning, AI investigation, web dashboard, and CI/CD integration. 14-day free trial.
Start free trial →Get threat intelligence and product updates
Security research, new threat signatures, and product updates. No spam.
Other clawhub scans
Believe this result is incorrect? Request a review or see our Terms of Service and Methodology.