plan-importer
Warn
Audited by Socket on Jul 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s behavior mostly matches its stated purpose and shows no clear credential theft or exfiltration, but it depends on executing a PlanWeave CLI whose official provenance could not be clearly verified from public evidence. That unverifiable external CLI requirement is the main risk driver; otherwise the skill is locally scoped and operationally coherent.
Confidence: 84%Severity: 78%
Audit Metadata