Back to skill

Security audit

Plane.so

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its stated Plane project-management purpose, but it installs an unverified remote executable that can use a Plane API token to change or delete workspace data.

Review before installing. Use a least-privilege Plane token if possible, avoid tokens with deletion/admin rights unless needed, and prefer an installer that pins a reviewed release and verifies a checksum or signature. Treat issue deletion as potentially irreversible.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:13
Finding

Mutable Remote CLI Is Downloaded and Executed Without Integrity Verification

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 29)May include surrounding context.

export PLANE_WORKSPACE="your-workspace-slug"

text

Get your API key from: **Plane → Profile Settings → Personal Access Tokens**

The workspace slug is the URL path segment (e.g., for `https://app.plane.so/my-team/` the slug is `my-team`).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill documents a destructive plane issues delete command without any warning, confirmation guidance, or safety guardrails. In an agent-skill context, this increases the chance of accidental irreversible issue deletion by users or automation acting on ambiguous instructions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.