to-spec

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose of drafting and publishing a spec, and the GitHub/GitLab CLIs are official. The main risks are autonomous external posting without explicit user confirmation, moderate prompt-injection exposure from synthesizing repo content before publishing, and transitive trust in /setup-skills whose behavior is not provided here.

Confidence: 86%Severity: 63%
Audit Metadata
Analyzed At
Aug 24, 2026, 03:06 PM
Package URL
pkg:socket/skills-sh/c0nant%2Fskills%2Fto-spec%2F@bcc6f610f8daf9c5959163e7a102a730aca8d38249b00b2cb0bf3c696e7340d8
Security Audit — socket — to-spec