plan-manager

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose and capabilities are coherent for local plan tracking, and there is no sign of credential theft or exfiltration. However, its core functionality relies on an undocumented local home-directory script with unverifiable provenance, which creates a high trust/supply-chain risk disproportionate to the lack of source verification.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:57 AM
Package URL
pkg:socket/skills-sh/notque%2Fclaude-code-toolkit%2Fplan-manager%2F@1b6531a7287d07d7fcc0a3f221f8e6227bebc311