execute-plan

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior is mostly consistent with a plan-execution skill and shows no obvious credential theft or external exfiltration, but it grants substantial local execution authority to plan-authored verification commands and chains into unspecified follow-on skills. Main risk is arbitrary command execution from untrusted plans plus transitive trust in `git-commit` and `/docs`, not confirmed malware.

Confidence: 85%Severity: 54%
Audit Metadata
Analyzed At
May 9, 2026, 05:02 AM
Package URL
pkg:socket/skills-sh/buiducnhat%2Fagent-skills%2Fexecute-plan%2F@ecb9511349a88d9f1bfc6f25084d3bc075941ad7