plan

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose and local file/CLI actions are broadly coherent, and there is no clear exfiltration or credential harvesting path. However, it materially depends on an unverifiable bespoke `doctrine` executable with no confirmed public provenance in the supplied evidence, which makes the trust footprint disproportionate enough to classify as suspicious rather than benign.

Confidence: 87%Severity: 75%
Audit Metadata
Analyzed At
Jul 25, 2026, 01:12 PM
Package URL
pkg:socket/skills-sh/davidlee%2Fdoctrine%2Fplan%2F@bd26b837c3cb8adc4b4121f0f93b39dd09c8d03c7bdb14684c6ad9e499ff30d9
Security Audit — socket — plan