plan-review-performance

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's stated purpose is benign and mostly aligned with its review capabilities, but the `npx skills add` instruction introduces transitive trust in a third-party skill source, and Bash permission is broader than necessary for a plan-review task. No direct credential theft or exfiltration is shown, so this is not confirmed malware, but it carries moderate security risk.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 16, 2026, 03:36 AM
Package URL
pkg:socket/skills-sh/ChristopherAlphonse%2Fcalphonse-skills%2Fplan-review-performance%2F@3071637856f10371d41ebba0fed0f6ce9f28be7f