spezi-platform-selection

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's stated purpose is coherent, and the Stanford Spezi Apple template appears legitimately same-org, but the workflow delegates execution trust to a hidden clone helper and then hands control to instructions and skills inside the cloned repository. That transitive trust chain is disproportionate to a simple platform-selection helper and creates medium security risk even without clear malicious intent.

Confidence: 81%Severity: 64%
Audit Metadata
Analyzed At
Mar 19, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/StanfordSpezi%2FSpeziVibe%2Fspezi-platform-selection%2F@8ca1eec679c454ae8a3d1f999087c6c44811508d
Security Audit — socket — spezi-platform-selection