plan

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill is primarily a local document management utility for plan.md, with generation and updating of a structured plan using a defined plan-generator. Its footprint is coherent with the stated purpose and largely benign in terms of data handling. The main security consideration is the use of an external npm/npx tool to install/run code, which could execute arbitrary logic at install-time. If the user trusts the npm package wintree86/plan-task-fix and the registry integrity, the risk remains low and proportional to typical developer tooling installation patterns. Monitor for unexpected network activity during installation and consider pinning the exact package/version or using a verified source to mitigate supply-chain concerns.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 11:30 PM
Package URL
pkg:socket/skills-sh/wintree86%2Fplan-task-fix%2Fplan%2F@c62c56b4afbdc890ddac8879482652d39371a7c1