plan-review-architecture

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose is coherent with its review-oriented instructions, and there is no evidence of credential harvesting, exfiltration, or hidden execution. The main concerns are ecosystem-level: transitive installation via `npx skills add` from a personal GitHub repo and somewhat broader-than-needed Bash access for an analytical skill. This looks more like medium trust/supply-chain risk than malicious behavior.

Confidence: 88%Severity: 52%
Audit Metadata
Analyzed At
May 16, 2026, 03:34 AM
Package URL
pkg:socket/skills-sh/ChristopherAlphonse%2Fcalphonse-skills%2Fplan-review-architecture%2F@fab052cbfc9ecbcb0d548ed006ac965247a1e746