spec-forge-implement

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the workflow behavior is coherent for an implementation-stage skill and there is no clear credential theft or exfiltration, but trust in the required `spec-forge-cli` is not well established from the skill text or public evidence. Main risk is unverifiable external CLI provenance, not malicious behavior in the skill itself.

Confidence: 86%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:30 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fspec-forge%2Fspec-forge-implement%2F@c0f07309621ce5736fe5c194c3e892713aa4892e
Security Audit — socket — spec-forge-implement