big-plan

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the core planning/GitHub capabilities fit the stated purpose, and most flagged command patterns are documentation artifacts, not malware. However, the skill’s autonomous handoff/merge behavior, GitHub mutation scope, untrusted-issue ingestion with write/exec powers, and fresh Claude launch with --dangerously-skip-permissions make it a high-impact workflow skill that exceeds low-risk planning guidance.

Confidence: 91%Severity: 74%
Audit Metadata
Analyzed At
Sep 21, 2026, 12:39 PM
Package URL
pkg:socket/skills-sh/takazudo%2Fclaude-resources%2Fbig-plan%2F@0a74afc72fd7330fd75b72b35cd04a08b5e29639556f5a07ef9aaca2b24832a9
Security Audit — socket — big-plan