planning-with-files

Warn

Audited by Socket on May 14, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.en.md

No clear malicious payload is evident in the provided configuration fragment (no explicit exfiltration, credential theft, or network indicators). However, the skill has Stop-time execution of local helper scripts selected via an environment-variable-based path, and the PowerShell path explicitly uses `-ExecutionPolicy Bypass`. This creates a meaningful arbitrary code execution risk if the `scripts/check-complete.*` files or the script directory location are compromised. Review/verify the referenced helper scripts and ensure the source is pinned and integrity-checked.

Confidence: 62%Severity: 62%
AnomalyLOW
SKILL.es.md

No direct malicious payload (exfiltration, credential theft, reverse shells) is visible in this manifest fragment. However, it executes platform-specific local helper scripts during the Stop lifecycle, and the Windows path explicitly uses PowerShell `-ExecutionPolicy Bypass`. Combined with script location derived from environment variables and the use of a moving upstream `master` source, this creates a meaningful supply-chain/execution risk that should be validated by inspecting `scripts/check-complete.ps1` and `scripts/check-complete.sh` and by pinning/reviewing upstream releases.

Confidence: 58%Severity: 57%
Audit Metadata
Analyzed At
May 14, 2026, 06:01 AM
Package URL
pkg:socket/skills-sh/minicoohei%2Fai-agent-camp%2Fplanning-with-files%2F@c7e8883ae98030c6729fed82e3a349ce50f79b03
Security Audit — socket — planning-with-files