planner

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core planning behavior is coherent and GitHub/Jira destinations are legitimate, but the Jira path materially increases risk: it sources raw credentials from local files and may execute an unverified local `jira-client.sh` helper or another skill. This is not confirmed malware, but the optional Jira integration makes the skill high-risk from an execution-trust and credential-handling perspective.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
Mar 18, 2026, 03:46 AM
Package URL
pkg:socket/skills-sh/goffity%2Fplanner-skills%2Fplanner%2F@db825c8da42d0dcc9ef85042e7b167cbd227d7fe