plan-importer

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s behavior mostly matches its stated purpose and shows no clear credential theft or exfiltration, but it depends on executing a PlanWeave CLI whose official provenance could not be clearly verified from public evidence. That unverifiable external CLI requirement is the main risk driver; otherwise the skill is locally scoped and operationally coherent.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Jul 16, 2026, 05:27 AM
Package URL
pkg:socket/skills-sh/GaosCode%2FPlanWeave%2Fplan-importer%2F@0650bf6dbffa337fe624c119c9e10bd1a17968eef127f2e3461ca68451fcd278
Security Audit — socket — plan-importer