plan-issue-codex
Warn
Audited by Socket on Apr 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
Medium risk. The skill's purpose and capability are aligned, but it delegates all behavior to a third-party npm package fetched and executed at runtime with `@latest`, creating a real supply-chain trust issue without clear evidence of malicious intent.
Confidence: 82%Severity: 58%
Audit Metadata