NYC

plan-validate

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected This skill is functionally aligned with its stated purpose: it reads local plan files, generates validation questions, collects answers, and appends a Validation Summary to plan.md. I found no signs of network exfiltration, obfuscated malicious code, credential harvesting, or hidden backdoors in the skill text. The main security consideration is operational: the agent runtime and AskUserQuestion/write tools could log or transmit plan contents or answers outside the local environment if misconfigured. Ensure the runtime is trusted and that tools do not leak sensitive data. Overall this skill appears benign for its intended use but requires standard operational safeguards around tooling and logging.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fplan-validate%2F@14be0a603fb8b254554c5cd5e57df7d138d33798