Skills alan-plan Audit History
📦

Audit History

alan-plan - 1 audit

Aug 20, 2026, 08:31 AM

All 29 static findings are false positives caused by Markdown backticks, fenced examples, Mermaid labels, and ordinary prose. No shell execution, system reconnaissance, or prompt injection appears in SKILL.md. The remaining medium risk is intended external persistence of repository-derived plans and context identifiers to Alan.

1
Files scanned
159
Lines analyzed
2
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Repository context is persisted to an external service
The skill requires sending the full repository-derived plan plus task, conversation, and team identifiers to Alan before user approval. Plans may expose sensitive architecture or internal names.
The instructions explicitly require codebase analysis and persistence of the complete plan with context identifiers through the Alan MCP tool.
Audited by: codex