spec-implement

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core orchestration behavior is coherent and mostly benign for its stated purpose, with official GitHub CLI usage and no obvious credential harvesting or exfiltration. The main concern is the transitive installation instruction for third-party worker skills via unpinned `npx skills add anyoneanderson/agent-skills`, which extends trust beyond this skill and raises supply-chain risk.

Confidence: 88%Severity: 63%
Audit Metadata
Analyzed At
May 15, 2026, 02:57 PM
Package URL
pkg:socket/skills-sh/anyoneanderson%2Fagent-skills%2Fspec-implement%2F@b9a6e4bd2755a5a6e4ecba46f7bf996723977c96
Security Audit — socket — spec-implement