spezi-platform-selection
Warn
Audited by Socket on Mar 19, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's stated purpose is coherent, and the Stanford Spezi Apple template appears legitimately same-org, but the workflow delegates execution trust to a hidden clone helper and then hands control to instructions and skills inside the cloned repository. That transitive trust chain is disproportionate to a simple platform-selection helper and creates medium security risk even without clear malicious intent.
Confidence: 81%Severity: 64%
Audit Metadata