Poteto Mode

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Security
SecurityMEDIUM
playbooks/worktree-cleanup.md

No malware or covert data-theft behavior is present because the fragment is an explicit cleanup playbook rather than executable package code. It presents a significant operational data-loss risk through forceful worktree, simulator, runtime, application-state, and cache deletion. Execution should require independent path validation, explicit confirmation for every non-clean or uncertain item, and avoidance of `rm -rf` unless the exact surviving path is verified.

Confidence: 98%Severity: 78%
Audit Metadata
Analyzed At
Sep 12, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/cursor%2Fplugins%2Fpoteto-mode%2F@286fadb34f85d74cbfdb7761ffdcbdddf6abbc4c
Security Audit — socket — Poteto Mode