candango-plan

Warn

Audited by Socket on May 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the wrapper’s stated purpose is coherent, but its core behavior is outsourced to a third-party skill from another publisher, creating a medium supply-chain and transitive-trust risk. The provided wrapper itself shows no credential harvesting or direct exfiltration, so this is not confirmed malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
May 26, 2026, 03:33 PM
Package URL
pkg:socket/skills-sh/lucasbayma%2Fskills%2Fcandango-plan%2F@518fe1dc642d44af25fd5028d7aa3302f9fd7f42
Security Audit — socket — candango-plan