roadmap-update

Warn

Audited by Socket on Feb 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] The analyzed fragment presents a well-structured, governance-centered automation plan for roadmap maintenance via a Claude plugin. It emphasizes traceability, auditable changes, and safe operation through HARD STOP prompts. While non-malicious in intent and design, operational rigor and correct configuration are critical to avoid destructive edits. The approach is appropriate for secure software supply chain operations when used with explicit approvals and proper access controls. LLM verification: This skill is functionally consistent with its stated purpose: it legitimately needs to read roadmap and changelog files and interact with git to mark tasks, draft releases, and push tags. It requires powerful repository-level permissions (file edits, commits, tags, and pushes) and executes pre-execution protocol files from the repository, which increases risk if those repository files are untrusted or can be modified by attackers. No direct malicious network calls, obfuscated payloads, or crede

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 23, 2026, 01:57 PM
Package URL
pkg:socket/skills-sh/parhumm%2Fjaan-to%2Froadmap-update%2F@15ebee5fd70c441608aa55a3eeab29db7e049c09