plot-deliver

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md describes a legitimate repository workflow: reading a plan file, verifying PR merge status and completeness, and performing repository updates to mark the plan Delivered. I find no evidence of obfuscated or exfiltrative code, no external untrusted downloads, and no hardcoded credentials. Primary risks: it requires running local scripts and executing gh/git commands (which use local credentials and perform repo writes), and it may perform automated PR state changes; operators should ensure the helper scripts are trusted and that the gh token used has appropriately limited scopes. Overall the content appears coherent with its stated purpose and not malicious.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 03:06 AM
Package URL
pkg:socket/skills-sh/eins78%2Fskills%2Fplot-deliver%2F@d667196ccd30b5d7f6e254b8fff02ebe564e775c