to-spec

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s stated purpose and data flows are mostly coherent for spec generation, but it executes unsupplied local helper scripts and can publish authoritative artifacts to shared systems. The main concern is execution trust/provenance of those local scripts rather than clear malicious intent or credential theft.

Confidence: 80%Severity: 72%
Audit Metadata
Analyzed At
Aug 18, 2026, 03:27 AM
Package URL
pkg:socket/skills-sh/rca32%2Fskills%2Fto-spec%2F@af87372d76ddb23f812795d9cc8d691bc97308d82914c5e5f24430b50037277e
Security Audit — socket — to-spec