plan-fix

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose mostly matches its capabilities, but it lets the agent ingest external analysis, clone an unspecified repo, execute repo-controlled builds, patch a product pack, and start services based on missing CLAUDE.md instructions. This is a coherent engineering workflow, not clear malware, yet the unresolved trust chain and execute-on-untrusted-content pattern create medium security risk.

Confidence: 82%Severity: 60%
Audit Metadata
Analyzed At
Apr 7, 2026, 08:11 AM
Package URL
pkg:socket/skills-sh/Tharsanan1%2Fwso2-se-agent-skills%2Fplan-fix%2F@0411d7fe5a660e5bad608399aee3d6875261371c