test-spec-gen
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core purpose is plausible, but the skill is overpowered for a test-spec generator: it combines silent multi-agent orchestration, external web/doc research, local config inspection, file writing, optional Trello actions, and delegation to other skills. The biggest concerns are indirect prompt injection from untrusted research sources and the transitive trust chain created by invoking additional skills; there is no strong evidence of outright credential theft or malware.
Confidence: 87%Severity: 68%
Audit Metadata