to-spec
Warn
Audited by Socket on Jul 11, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and actions mostly align, and it does not seek disproportionate credentials or obvious exfiltration. The main risk is the unpinned `uvx disambiguate` dependency: it may fetch and execute an unverified package at runtime, which is unnecessary supply-chain exposure for a documentation/spec-writing skill. Without proof of the package publisher or a pinned version/source, the install/execution trust is only partially coherent.
Confidence: 84%Severity: 62%
Audit Metadata