to-spec

Warn

Audited by Socket on Jul 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and actions mostly align, and it does not seek disproportionate credentials or obvious exfiltration. The main risk is the unpinned `uvx disambiguate` dependency: it may fetch and execute an unverified package at runtime, which is unnecessary supply-chain exposure for a documentation/spec-writing skill. Without proof of the package publisher or a pinned version/source, the install/execution trust is only partially coherent.

Confidence: 84%Severity: 62%
Audit Metadata
Analyzed At
Jul 11, 2026, 04:58 PM
Package URL
pkg:socket/skills-sh/frankify-app%2Fskills%2Fto-spec%2F@ff0042f466f5ac4eada3d7c048920005bf5487a02077c5399bc817f99409aaf4
Security Audit — socket — to-spec