wave-plan-pipeline

Fail

Audited by Socket on Feb 28, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The activity depicts a robust, CSV-driven orchestration framework for phased exploration and execution with cross-phase context. While the design aligns with structured planning and traceability, the heavy reliance on external agents and append-only shared artifacts introduces notable supply-chain and data-flow risks. No direct credentials or exfiltration is evident in the fragment, but command-template injection and stateful session resumption warrant mitigations (input validation, sandboxed agent execution, strict access controls). Overall, the approach is powerful but requires stringent controls to be considered acceptable in production.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 28, 2026, 08:29 AM
Package URL
pkg:socket/skills-sh/catlog22%2Fclaude-code-workflow%2Fwave-plan-pipeline%2F@25996c6d3f1aa90784f58696fce6666b5019bc1a