feature-implementation

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches a TDD implementation assistant, but it has a broad execution footprint: autonomous code/doc changes, browser-driven acceptance testing, and optional database SQL validation. There is no clear malicious install path or third-party credential harvesting, yet the combination of MCP-powered browser/database access and write/exec capability creates medium security risk, especially if used against untrusted app content or non-development data.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 19, 2026, 10:11 AM
Package URL
pkg:socket/skills-sh/MingYuePop%2FSpecForge%2Ffeature-implementation%2F@56d4a96ecb8a0a7271352221f4be833de2b22a5b
Security Audit — socket — feature-implementation