spec-forge-cli

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
.releaserc.json

No explicit malicious code or secrets are present in the provided semantic-release configuration fragment. The dominant risk signal is that the release pipeline executes multiple custom local Node scripts via @semantic-release/exec during both prepare and publish phases, and the resulting artifacts are uploaded and published. This warrants direct review and integrity verification of scripts/release/*.mjs to rule out tampering, credential misuse, unexpected network activity, or backdoored artifacts.

Confidence: 56%Severity: 62%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:36 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fspec-forge%2Fspec-forge-cli%2F@163f5a33d9098c434b8d967d6ce4a3212a871064
Security Audit — socket — spec-forge-cli