planr-status

Warn

Audited by Socket on Mar 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose is coherent and its data flows are local and proportionate, but it requires executing an unverifiable repo-local CLI. That trust issue alone makes the skill high-risk from an execution/supply-chain standpoint, even though there is no evidence here of credential theft, external exfiltration, or overtly malicious behavior.

Confidence: 85%Severity: 72%
Audit Metadata
Analyzed At
Mar 18, 2026, 04:48 AM
Package URL
pkg:socket/skills-sh/regenrek%2Fcodex-planr%2Fplanr-status%2F@53a3ed28ca072c38ae5308e927f4374fe67f595e