plankton-code-quality

Warn

Audited by Socket on Mar 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is broadly consistent with a code-quality automation purpose, but it adds a nontrivial trust and execution surface by cloning a personal GitHub repo, running local setup/hooks, and silently spawning Claude subprocesses on every edit. No clear credential harvesting or off-purpose exfiltration is shown, so this is not malicious, but the install and autonomous execution model create medium security risk.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Mar 22, 2026, 10:30 AM
Package URL
pkg:socket/skills-sh/affaan-m%2Feverything-claude-code%2Fplankton-code-quality%2F@afe63f4f458c3d60b4421eff29e82c8beb3254ac