deepen-plan

Warn

Audited by Socket on Mar 25, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core task is plausible, but the implementation is over-broad and unsafe for a plan-deepening skill. Its main risk is transitive execution of arbitrary installed skills/agents from local and plugin sources, combined with untrusted-content ingestion and broad autonomous orchestration.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Mar 25, 2026, 02:06 AM
Package URL
pkg:socket/skills-sh/everyinc%2Fcompound-engineering-plugin%2Fdeepen-plan%2F@0f70fc552fe6d44de3f03d6b4c1a21a37ffcc64d