deepen-plan

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plan enhancement, but the actual footprint is much broader. The main issue is transitive trust: it enumerates and executes arbitrary local/plugin skills and agents, tells sub-agents to follow their instructions exactly, and combines that with external research sources and file writes. There is no clear malware payload or credential theft logic, but the scope and trust expansion are disproportionate and create high supply-chain and prompt-injection risk.

Confidence: 87%Severity: 81%
Audit Metadata
Analyzed At
Mar 13, 2026, 07:26 PM
Package URL
pkg:socket/skills-sh/EveryInc%2Fcompound-engineering-plugin%2Fdeepen-plan%2F@91200121a3e59ba86da2954a423f629e01f9cdd2