spec-forge-implement
Warn
Audited by Socket on Apr 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the workflow behavior is coherent for an implementation-stage skill and there is no clear credential theft or exfiltration, but trust in the required `spec-forge-cli` is not well established from the skill text or public evidence. Main risk is unverifiable external CLI provenance, not malicious behavior in the skill itself.
Confidence: 86%Severity: 58%
Audit Metadata