plan-ceo-strategy
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core behavior is a benign strategy-review guide, but the included `npx skills add` instruction installs a separate third-party skill and creates a transitive trust risk unrelated to the narrow planning task. Bash permission is also broader than necessary, though there is no direct credential theft or exfiltration behavior in the visible skill.
Confidence: 86%Severity: 55%
Audit Metadata