plugin-lifecycle

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s capabilities mostly match its stated plugin-lifecycle purpose, but it expands trust through transitive skill loading and repeated unpinned `uvx ...@latest` execution. Data flows and file access are otherwise coherent with plugin development, and there is no clear credential harvesting or exfiltration behavior.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 29, 2026, 08:43 AM
Package URL
pkg:socket/skills-sh/Jamie-BitFlight%2Fclaude_skills%2Fplugin-lifecycle%2F@97487f8ce15a15e0ae5298cd8d511965d2cbf58f