writer-planner

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill’s stated purpose and visible behavior mostly align: it converts documents/URLs into markdown and planning artifacts. The main security issue is trust in the undocumented local wa-* executables that the skill requires and runs; because their provenance is not verifiable from the provided material, this is a high supply-chain risk even without clear malicious behavior. No credential harvesting or hostile data-routing is evident, so this is best classified as SUSPICIOUS rather than malicious.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Apr 22, 2026, 04:37 PM
Package URL
pkg:socket/skills-sh/hoangvantuan%2Fclaude-plugin%2Fwriter-planner%2F@5ef5068e3968a205f6852eb5e20f9bbf735fdc23
Security Audit — socket — writer-planner