speckit-wizard

Warn

Audited by Socket on Mar 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core spec-generation behavior is benign and locally scoped, but the skill also enables autonomous code changes, validation, and commits while referring to loosely defined Ralph/Archon integrations. No clear credential theft or exfiltration is present, yet the implementation-loop footprint is broader than a documentation/spec wizard and merits medium risk.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 15, 2026, 11:10 AM
Package URL
pkg:socket/skills-sh/HouseGarofalo%2Fclaude-code-base%2Fspeckit-wizard%2F@be98509beb7aafb2cb62d192ddf40063a35423d6