seemseam-plan-tree

v0.2.1 suspicious
5.0
Medium Risk

Installer for the portable plan-tree AI planning skill.

🤖 AI Analysis

Final verdict: SUSPICIOUS

The package has a moderate risk score due to metadata concerns such as recent upload and inactive maintenance, despite having low risks in network, shell, obfuscation, and credential areas.

  • Recent upload and inactive maintenance increase suspicion.
  • Potential supply-chain attack cannot be ruled out.
Per-check LLM notes
  • Network: The package downloads files from external URLs, which could be legitimate if the sources are trusted and the purpose is documented.
  • Shell: No shell execution patterns detected, indicating a low risk of direct system command execution.
  • Obfuscation: No obfuscation patterns detected, indicating low risk.
  • Credentials: No credential harvesting patterns detected, indicating low risk.
  • Metadata: The package seems suspicious due to its recent upload and the maintainer's inactivity, indicating potential risk.

🔬 Heuristic Checks

⚠ Outbound Network Calls score 1.5

Found 1 network call pattern(s)

  • int(f"Downloading {url}") urllib.request.urlretrieve(url, archive_path) with zipfile.ZipFile(arc
✓ Code Obfuscation

No obfuscation patterns detected

✓ Shell / Subprocess Execution

No shell execution patterns detected

✓ Credential Harvesting

No credential harvesting patterns detected

✓ Typosquatting

No typosquatting candidates detected

✓ Registered Email Domain

No author email provided

✓ Suspicious Page Links

All external links appear legitimate

✓ Git Repository History

Repository SeemSeam/plan-tree appears legitimate

⚠ Maintainer History score 6.0

3 maintainer concern(s) found

  • Only one version has ever been released — brand new package
  • Package uploaded less than 24 hours ago (2026-06-05T03:03:33.000Z)
  • Author "SeemSeam" appears to have only 1 package on PyPI (new or inactive account)

💬 Discussion Feed

Leave a comment

No discussion yet. Be the first to share your thoughts!