vercel-plugin-eval
Warn
Audited by Socket on Mar 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s stated purpose matches plugin evaluation, but its footprint is moderately risky because it installs a plugin from a GitHub URL and launches real Claude Code sessions that can act on injected prompts. The local log inspection is proportionate to debugging, but the combination of third-party plugin installation and action-capable session spawning raises medium security concern.
Confidence: 80%Severity: 64%
Audit Metadata