main

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The file is a planning/router orchestration document that, by itself, does not contain clear malicious payloads. However, it prescribes high-risk operational rules: mandatory invocation of any possibly-relevant skill and automatic execution of a local init script. These behaviors expand the attack surface and enable downstream code execution or data exfiltration by invoked skills or scripts. Treat this component as a medium security risk: it is a facilitator of supply-chain and execution risks. Recommend adding explicit verification, consent gates, an allowlist or signature validation for skills and init scripts, and sandboxing of invoked skill execution.

Confidence: 98%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 01:41 PM
Package URL
pkg:socket/skills-sh/sipengxie2024%2Fsuperpower-planning%2Fmain%2F@9a396326c556c5f141feaaf01eec8db87dab646c