spec-forge-intake

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and local file-writing behavior are coherent for a spec-intake workflow, and there is no evident credential harvesting or exfiltration. However, it requires an unverifiable external CLI with no trustworthy install or publisher evidence in the provided material, which is a significant supply-chain risk for an AI agent skill.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:30 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fspec-forge%2Fspec-forge-intake%2F@e321eb5009d6090635226d89ab7f05c9cfe04262
Security Audit — socket — spec-forge-intake