planning-with-files
Audited by Socket on May 14, 2026
2 alerts found:
Anomalyx2No clear malicious payload is evident in the provided configuration fragment (no explicit exfiltration, credential theft, or network indicators). However, the skill has Stop-time execution of local helper scripts selected via an environment-variable-based path, and the PowerShell path explicitly uses `-ExecutionPolicy Bypass`. This creates a meaningful arbitrary code execution risk if the `scripts/check-complete.*` files or the script directory location are compromised. Review/verify the referenced helper scripts and ensure the source is pinned and integrity-checked.
No direct malicious payload (exfiltration, credential theft, reverse shells) is visible in this manifest fragment. However, it executes platform-specific local helper scripts during the Stop lifecycle, and the Windows path explicitly uses PowerShell `-ExecutionPolicy Bypass`. Combined with script location derived from environment variables and the use of a moving upstream `master` source, this creates a meaningful supply-chain/execution risk that should be validated by inspecting `scripts/check-complete.ps1` and `scripts/check-complete.sh` and by pinning/reviewing upstream releases.