writing-specs

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The writing-specs workflow fragment is largely benign and purpose-aligned, providing a lean, constitution-adherent method for generating feature specifications with clear run-scoped isolation. The main concerns are operational and environmental: ensure trusted sources for setup commands (CLAUDE.md), validate inputs to prevent injection in automated shells, and implement safeguards around git worktree operations and spec file access. With these mitigations, the workflow remains suitable for secure, auditable spec generation.

Confidence: 68%Severity: 60%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:48 AM
Package URL
pkg:socket/skills-sh/arittr%2Fspectacular%2Fwriting-specs%2F@759c0c3451d0ed499f12124fde6b87f50e843079