plan-eng-review

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a code-review/planning skill, and no direct credential theft or external exfiltration is visible. However, it depends on unverifiable local gstack executables and an opaque upgrade-skill chain; that install/execution trust issue is disproportionate enough to make the skill high security risk even without confirmed malware.

Confidence: 85%Severity: 78%
Audit Metadata
Analyzed At
Mar 16, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fplan-eng-review%2F@ca51e4f286fd30f4dc53b421e47b202b919d48e8