eng-spec

Warn

Audited by Socket on Apr 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core document-generation and review behavior is aligned with the stated purpose, and there is no clear credential harvesting or malicious exfiltration path. Risk comes from high workflow autonomy, ingestion of potentially untrusted project content while retaining write/exec capability, and invocation of undocumented local CLIs whose behavior and provenance are not verifiable from the skill alone.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Apr 2, 2026, 09:46 AM
Package URL
pkg:socket/skills-sh/amit-t%2Fskills%2Feng-spec%2F@102cc05548ead7ba931d5335f0898131fd8d4c60