plugins-management

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities fit its stated plugin-management purpose, and verified references to GitHub CLI, OpenCode docs, and npm are legitimate. The main risk is inherent supply-chain exposure from helping the agent install/publish/manage third-party plugins from npm and arbitrary marketplace URLs, which can introduce highly privileged code, but there is no clear credential theft, hidden execution, or malicious exfiltration in this skill itself.

Confidence: 89%Severity: 56%
Audit Metadata
Analyzed At
Sep 22, 2026, 02:48 AM
Package URL
pkg:socket/skills-sh/codealive-ai%2Fai-driven-development%2Fplugins-management%2F@295c26fac41b61ef30884c436a98c635b6cb59cbc14c2d7af28315866b32891c
Security Audit — socket — plugins-management