Plop.js Code Generator
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS due to transitive skill installation and only partially verified publisher trust, not because the stated Plop.js functionality is itself abnormal. The footprint is broadly aligned with a code-generation skill, but the install model loads remote skill instructions through third-party registries/repos, so overall risk is medium-high even without evidence of credential theft or malicious payloads.
Confidence: 87%Severity: 72%
Audit Metadata