plan-review-performance
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's stated purpose is benign and mostly aligned with its review capabilities, but the `npx skills add` instruction introduces transitive trust in a third-party skill source, and Bash permission is broader than necessary for a plan-review task. No direct credential theft or exfiltration is shown, so this is not confirmed malware, but it carries moderate security risk.
Confidence: 88%Severity: 56%
Audit Metadata