spec-kitty-dashboard

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is a workflow wrapper, but its real functionality is delegated to an unverifiable external CLI/plugin with no provenance or install trust evidence. The skill also instructs the agent to trust that opaque output over local context, which is disproportionate and creates a high supply-chain and transitive-trust risk even without clear evidence of credential theft.

Confidence: 83%Severity: 78%
Audit Metadata
Analyzed At
Apr 27, 2026, 08:42 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fspec-kitty-dashboard%2F@c1772c3b55cf0292319c06fdb5cf4416ca98f98f