se-dev-plugin

Warn

Audited by Socket on May 9, 2026

1 alert found:

Anomaly
AnomalyLOW
Prepare.md

The described procedure is functionally simple but exposes a moderate-to-high supply-chain risk because it executes an unverified local batch file and relies solely on a writable log sentinel ('DONE') as the success criterion. An attacker who can modify repository files can trivially achieve persistence or arbitrary execution while making the run appear successful. Recommendations: inspect Prepare.bat before running, verify provenance (signed release or checked checksum), run it in an isolated environment (VM/container) or under restricted privileges, and replace the single-line log check with stronger artifact and exit-code validation. Do not run untrusted Prepare.bat files on production or sensitive hosts.

Confidence: 75%Severity: 60%
Audit Metadata
Analyzed At
May 9, 2026, 09:10 PM
Package URL
pkg:socket/skills-sh/viktor-ferenczi%2Fse-dev-skills%2Fse-dev-plugin%2F@7dd65598f5335a1f0959a1ddfcc06fc179370099
Security Audit — socket — se-dev-plugin