plan-executor

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The code fragment depicts a coherent orchestration tool for plan-based multi-agent execution, with clear separation of duties, user confirmation gates, and per-task SubAgent prompts. It exhibits no obvious malicious activity, credential handling, or external data exfiltration within the fragment. The primary concerns are prompt/data exposure through SubAgent prompts and potential template staleness or plan non-conformity, which are manageable through existing safeguards (confirmation step, template design, and validation). Overall, a sound, purpose-aligned orchestration component with moderate operational risk centered on prompt/data exposure and dependency parsing robustness.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:08 PM
Package URL
pkg:socket/skills-sh/Vamdawn%2Fai-forge%2Fplan-executor%2F@1036e83b7bc970f6f35eb8e1c34abb36f92f6355