plannotator

Warn

Audited by Socket on Mar 23, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s stated purpose mostly matches its capabilities, but it expands trust through repo-run install scripts, plugin installation, and undocumented sharing endpoints. The main concern is medium supply-chain and data-flow uncertainty rather than confirmed malicious behavior.

Confidence: 71%Severity: 59%
AnomalyLOW
scripts/install.sh

The script is a typical installer wrapper with optional integration setup. The major security concern is the remote installer execution via curl | bash, which can run unverified code from an external source. This is a high-risk pattern (source-to-sink path) and should be mitigated by using verified installers, checksums/signatures, or downloading to a file and running with explicit verification. Otherwise, the script itself contains no overt malicious behavior, but relies on external remote code that could compromise the system if the remote source is compromised.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Mar 23, 2026, 02:07 PM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-unity3d%2Fplannotator%2F@d0aa2a1d7a9524266b72780a43c6f06acb3083bc