audit-plugin

Warn

Audited by Socket on Apr 3, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, but it extends execution trust to a separate unbundled plugin and sibling shell scripts via relative paths. Data flow stays local and there is no clear credential exfiltration, so this is not malicious, but the cross-plugin execution model and broader-than-needed permissions raise medium risk.

Confidence: 81%Severity: 56%
Audit Metadata
Analyzed At
Apr 3, 2026, 06:09 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Faudit-plugin%2F@ca3ca170a0319554ced71cf9e254a621d19f7803