smp-pm
Warn
Audited by Socket on May 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent for project-management automation, but the skill's trust model is weak because it requires an unverifiable external `smp` CLI and forwards `SMP_TOKEN` to it. The data flows are proportionate to PM work, yet the unverified binary plus credential forwarding makes this a high-risk skill rather than a benign guide.
Confidence: 83%Severity: 84%
Audit Metadata