plugin-lifecycle
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated plugin-lifecycle purpose, but it expands trust through transitive skill loading and repeated unpinned `uvx ...@latest` execution. Data flows and file access are otherwise coherent with plugin development, and there is no clear credential harvesting or exfiltration behavior.
Confidence: 84%Severity: 61%
Audit Metadata