plantuml

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's footprint is coherent with its stated purpose: it derives data from context, renders a PlantUML diagram, and outputs a markdown image path. It relies on locally installed tools (emacsclient and PlantUML) and uses a session-scoped color, with temporary file handling in /tmp. The data access is limited to local context and UI color data; there is minimal risk of credential exposure or remote exfiltration. Minor concerns include lack of explicit error handling for tool availability and ephemeral /tmp file cleanup, but these do not undermine the intended functionality or pose significant security risk in typical developer environments.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 08:51 PM
Package URL
pkg:socket/skills-sh/xenodium%2Femacs-skills%2Fplantuml%2F@38d8a615c8bfb8e9f11ce4085d326910a967b367