foundry-security-spec

Warn

Audited by Socket on May 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill is broadly coherent as a blueprint for an AI-driven security evaluation system, but it carries high inherent risk because it enables offensive security workflows, sandboxed testing, and external publishing. The main inconsistency is install trust: it claims nothing needs installation while directing users to install Spec Kit, and the npm install command appears inconsistent with GitHub's official documentation. No clear malware or credential-harvesting behavior is shown, but the capability set is powerful and should be treated as high-risk.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
May 22, 2026, 10:54 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fsecurity-skills%2Ffoundry-security-spec%2F@9e58da221bb45a93d4e3505ca24e577d753b9160
Security Audit — socket — foundry-security-spec