plan-ceo-wrapup

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core behavior is a narrow local planning/writing workflow and is mostly coherent, but the skill requests unnecessary Bash access and is distributed through a transitive third-party skill installation from a personal GitHub repo. No direct credential theft or exfiltration is evident, so this looks more like medium supply-chain/trust risk than malware.

Confidence: 87%Severity: 53%
Audit Metadata
Analyzed At
May 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/ChristopherAlphonse%2Fcalphonse-skills%2Fplan-ceo-wrapup%2F@68757519853bee36eef52e01802574b9d0297018