wave-planner

Warn

Audited by Socket on Mar 5, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/execution-checklist.md

The workflow presents a high-level orchestration plan with several security risk vectors around dynamic skill loading, multi-gate approvals, and inter-agent handoffs. While the plan outlines a comprehensive process, it lacks explicit authentication, provenance tracking, input/output validation, and auditable logging. Implementing strict access controls, provenance verification for dynamic components, signed and validated plan artifacts, and secure, auditable inter-agent communication is essential before deployment. Recommend adding: authenticated identity for gates, verifiable integrity checks for acpx skills, signing and versioning for plans, tamper-evident logging, and a defined audit trail for all handoffs and state transitions.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Mar 5, 2026, 09:55 AM
Package URL
pkg:socket/skills-sh/Asm3r96%2Fwave-driven-dev%2Fwave-planner%2F@3eb8a3d9ce895c77e6ab5a902a415f4c9924ac83