planning-and-task-breakdown

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The planning behavior is coherent and mostly local, but the skill depends on an unverifiable solo CLI with no documented publisher, install path, or release provenance. With no credentials or network routing in the skill, this looks like a supply-chain trust issue rather than confirmed malicious behavior.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
May 7, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/v1truv1us%2Fai-eng-system%2Fplanning-and-task-breakdown%2F@889a09f1a9dcf5ff6f4e89427337edee6a8f885c