spec-forge-architecture

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated planning purpose is coherent with its local file reads/writes, and there is no sign of credential theft or external exfiltration. The main issue is install/execution trust: it relies on an opaque `spec-forge-cli` with no verified official provenance in the provided evidence, which makes the skill higher risk than a pure documentation-only workflow.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:30 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fspec-forge%2Fspec-forge-architecture%2F@4d2e6eb789e3fc4a3b01394b13dc293a16ccc571
Security Audit — socket — spec-forge-architecture