openspec-onboard

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core OpenSpec onboarding flow is broadly consistent with its stated purpose and uses an official CLI, but the skill expands trust by invoking other skills and suggesting installation of another skill, while also processing untrusted repo content and enabling write/implementation actions. No clear credential theft or explicit exfiltration is present, so this is not malicious, but the transitive-skill and prompt-injection exposure make it medium risk.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Aug 31, 2026, 08:21 PM
Package URL
pkg:socket/skills-sh/redhat-developer%2Frhdh-skills%2Fopenspec-onboard%2F@5123c48bcc0a2cebd279f18341797ac337511d9d195d480e6b56ee79a092012f
Security Audit — socket — openspec-onboard