spec-forge-journeys

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The workflow is purpose-aligned and mostly local, with no clear exfiltration or credential abuse, but it requires a non-publicly verifiable `spec-forge-cli` executable. That black-box dependency is disproportionate from a trust perspective and raises high supply-chain risk despite otherwise coherent behavior.

Confidence: 84%Severity: 78%
Audit Metadata
Analyzed At
Apr 28, 2026, 09:30 AM
Package URL
pkg:socket/skills-sh/ByteLandTechnology%2Fspec-forge%2Fspec-forge-journeys%2F@56fab7cf686485f779fb43a88a099cbe0f34f44d
Security Audit — socket — spec-forge-journeys