nextstage-spec-driven

Warn

Audited by Socket on Jul 24, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill’s purpose and capabilities mostly align for a project-delivery orchestrator, and the explicit installer path is a same-brand npm package rather than an obviously rogue payload. The main concern is transitive trust: it delegates to many worker skills and recommends installing complement skills via a preset without exposing the exact downstream instructions or permissions in this artifact. No direct credential harvesting, exfiltration endpoint, pre-execution shell directive, or unverifiable binary is evident here, so this is not malicious, but it carries medium risk due to broad delegation and skill-install chaining.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Jul 24, 2026, 08:26 PM
Package URL
pkg:socket/skills-sh/nextstage-brasil%2Fskills%2Fnextstage-spec-driven%2F@a3193cb3543387389347b1cf8b1878d70e5e88f4e347010b70c0fb5f60be5782
Security Audit — socket — nextstage-spec-driven