plotloom-asset-selection

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS due to install/execution trust, not behavior. The skill’s purpose and local file actions are coherent for asset selection, and there is no sign of credential theft or exfiltration, but it relies on an unverifiable plotloom CLI with no confirmed official distribution path in the supplied evidence.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Apr 30, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/T0UGH%2Fplotloom%2Fplotloom-asset-selection%2F@79e4a3c09d6e7a58c9c24430c7b7c671524c221a
Security Audit — socket — plotloom-asset-selection