plan-manager
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose and capabilities are coherent for local plan tracking, and there is no sign of credential theft or exfiltration. However, its core functionality relies on an undocumented local home-directory script with unverifiable provenance, which creates a high trust/supply-chain risk disproportionate to the lack of source verification.
Confidence: 90%Severity: 72%
Audit Metadata