mvp-spec

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

Suspicious but not malicious. The skill is internally coherent as an analysis-to-spec orchestrator, and there is no external install path, credential request, or remote exfiltration. Main risk is disproportionate autonomy: it chains hidden local skills, processes untrusted external content, may run tests/builds, and writes local telemetry without explicit per-action approval.

Confidence: 89%Severity: 52%
Audit Metadata
Analyzed At
Mar 23, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/tinh2%2Fskills-hub-registry%2Fmvp-spec%2F@ff384ffae65b31e9c5c583d840d0f3db2786194f
Security Audit — socket — mvp-spec