pm

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
references/workflows/allow.md

The fragment provides a legitimate automation for convenience but lowers runtime security prompts and persists permissions. In trusted automation scenarios this is acceptable with strong integrity controls; in untrusted contexts, it creates a privilege escalation risk and a persistently actionable configuration change. Recommend scoped, auditable, time-bound permissions, explicit validation, and signing of agent-kit/plugin updates to mitigate risk.

Confidence: 52%Severity: 58%
Audit Metadata
Analyzed At
May 11, 2026, 01:37 AM
Package URL
pkg:socket/skills-sh/cloudvoyant%2Fcodevoyant%2Fpm%2F@d60fd9f967ab672f72f872d24c98f179c2c50fb2