openspec-to-beads

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill functions as a workflow orchestration bridge with read-access to planning artifacts and write-access to Beads issues. Its footprint is coherent with a legitimate development tooling scenario, focusing on traceability and proactive gap detection. No obvious credential harvesting, remote execution, or data exfiltration patterns are present. The main risk is misconfiguration leading to unintended data exposure in issue descriptions or improper task prioritization; mitigations include strict access controls, audit logging, and verified templates.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 08:44 PM
Package URL
pkg:socket/skills-sh/cachemoney%2Fagent-toolkit%2Fopenspec-to-beads%2F@93c8c37a8e18a13f84eb5d26a66a86b314279c63