plankton-code-quality
Warn
Audited by Socket on Mar 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is broadly consistent with a code-quality automation purpose, but it adds a nontrivial trust and execution surface by cloning a personal GitHub repo, running local setup/hooks, and silently spawning Claude subprocesses on every edit. No clear credential harvesting or off-purpose exfiltration is shown, so this is not malicious, but the install and autonomous execution model create medium security risk.
Confidence: 86%Severity: 58%
Audit Metadata