plugin-updater

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The stated purpose matches plugin management, but the skill's trust model is weak because it executes third-party cached scripts by discovery rather than verified provenance. No clear credential theft or exfiltration is shown, yet the combination of auto-updating and arbitrary local script execution from plugin cache makes this a medium-high supply-chain risk.

Confidence: 87%Severity: 64%
Audit Metadata
Analyzed At
Apr 29, 2026, 12:29 PM
Package URL
pkg:socket/skills-sh/diegomarino%2Fclaude-toolshed%2Fplugin-updater%2F@869690f04f05f0a1a57a20ad91abb177e0dcd52a
Security Audit — socket — plugin-updater