T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:13- Finding
Mutable Remote CLI Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated Plane project-management purpose, but it installs an unverified remote executable that can use a Plane API token to change or delete workspace data.
Review before installing. Use a least-privilege Plane token if possible, avoid tokens with deletion/admin rights unless needed, and prefer an installer that pins a reviewed release and verifies a checksum or signature. Treat issue deletion as potentially irreversible.
SKILL.md:13Mutable Remote CLI Is Downloaded and Executed Without Integrity Verification
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
export PLANE_WORKSPACE="your-workspace-slug"
Get your API key from: **Plane → Profile Settings → Personal Access Tokens**
The workspace slug is the URL path segment (e.g., for `https://app.plane.so/my-team/` the slug is `my-team`).
The skill documents a destructive plane issues delete command without any warning, confirmation guidance, or safety guardrails. In an agent-skill context, this increases the chance of accidental irreversible issue deletion by users or automation acting on ambiguous instructions.
No suspicious patterns detected.