Plop.js Code Generator Orchestrator
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is plausible, but the install path depends on transitive skill installation from an unverified third-party repo target. The main issue is supply-chain and trust inconsistency rather than overt malicious behavior or credential theft.
Confidence: 84%Severity: 74%
Audit Metadata