planning-loop

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is purpose-aligned for autonomous game design, but its actual footprint is high-risk because it defaults to unattended Claude sessions with --dangerously-skip-permissions, ingests untrusted web content, writes/commits files, and auto-pushes to a git remote. No clear credential harvesting or malicious exfiltration is present, so this is not confirmed malware, but it is a high-risk autonomous agent workflow.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Mar 22, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/RiccardoGrin%2Fskills%2Fplanning-loop%2F@af4edcdb57386ff12f987ef24df2d09ec7f5e375
Security Audit — socket — planning-loop