plan

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
references/workflows/allow.md

No direct evidence of malware is present in the provided configuration/permission-update fragment. However, it is explicitly designed to suppress permission prompts by expanding and persisting a Claude Code `.permissions.allow` policy, including broad read access to skill/plugin reference directories outside the project boundary. The security concern is authorization control weakening and increased blast radius if referenced workflows/plugins are compromised or if the derived allow entries become broader than intended.

Confidence: 55%Severity: 55%
Audit Metadata
Analyzed At
Aug 31, 2026, 06:32 PM
Package URL
pkg:socket/skills-sh/cloudvoyant%2Fcodevoyant%2Fplan%2F@8812de03827bc3f3d47365e3ae1b5b2af1d7d9f19ef927b0e5b0e528ed206ecd
Security Audit — socket — plan