plan-feature-from-youtrack

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and local file access are coherent, but its core dependency is an external yt CLI with unverifiable provenance in the provided evidence, and that CLI receives YouTrack credentials. That combination makes the skill high risk despite otherwise plausible functionality.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
Apr 22, 2026, 10:18 PM
Package URL
pkg:socket/skills-sh/xpepper%2Fplan-feature-from-youtrack-agent-skill%2Fplan-feature-from-youtrack%2F@3fa3caa9c3e7b009175a2c8708428461b268eff4