spec-review

Warn

Audited by Socket on May 7, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, but it gives a subagent authority to execute repository code and autonomously trigger follow-on actions from untrusted diff/content. There is no clear credential harvesting or off-platform exfiltration, so this is not malicious, but the combination of command execution plus autonomous workflow transitions makes it medium/high risk.

Confidence: 87%Severity: 71%
Audit Metadata
Analyzed At
May 7, 2026, 04:37 AM
Package URL
pkg:socket/skills-sh/lvlup-sw%2Fexarchos%2Fspec-review%2F@1dad900c6d2592a60db8b8858f88eb876cdfbb9a