openspec-archive
Warn
Audited by Socket on Aug 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core archive behavior is coherent with an OpenSpec workflow, but the skill’s footprint is broader than necessary: it introduces a separate third-party CodeGraph CLI, can trigger transitive skill execution, and optionally performs external PR creation. No direct credential theft or exfiltration is evident, but install-trust and action-scope risks make it higher than a simple archival helper.
Confidence: 87%Severity: 61%
Audit Metadata