big-plan
Warn
Audited by Socket on Sep 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core planning/GitHub capabilities fit the stated purpose, and most flagged command patterns are documentation artifacts, not malware. However, the skill’s autonomous handoff/merge behavior, GitHub mutation scope, untrusted-issue ingestion with write/exec powers, and fresh Claude launch with --dangerously-skip-permissions make it a high-impact workflow skill that exceeds low-risk planning guidance.
Confidence: 91%Severity: 74%
Audit Metadata