openspec-archive

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core archive behavior is coherent with an OpenSpec workflow, but the skill’s footprint is broader than necessary: it introduces a separate third-party CodeGraph CLI, can trigger transitive skill execution, and optionally performs external PR creation. No direct credential theft or exfiltration is evident, but install-trust and action-scope risks make it higher than a simple archival helper.

Confidence: 87%Severity: 61%
Audit Metadata
Analyzed At
Aug 14, 2026, 05:54 PM
Package URL
pkg:socket/skills-sh/te-quanbzhang%2Fskills-pool%2Fopenspec-archive%2F@b8d66b01b43f2ffbfff581c7ab40e838061ed330064706d1a95548323b70cd16
Security Audit — socket — openspec-archive