spec-add

Fail

Audited by Socket on Mar 8, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The spec-add skill concept is coherent with its stated purpose: it gathers rules/conventions/learning items and stores them locally in project or personal spec files, with optional interactive mode and auto-confirm workflows. There are no evident data exfiltration or credential harvesting vectors, and the only external actions are controlled invocations of interior tooling commands. The security footprint is benign to moderate, with minor concerns around shell invocation in combination with user-provided inputs, and local data storage in user directories. Overall, the footprint is proportionate to the task and maintains a low risk posture, but keep an eye on ensuring that interactive prompts cannot be abused to trigger unintended shell actions in extended implementations.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 8, 2026, 04:10 PM
Package URL
pkg:socket/skills-sh/catlog22%2FClaude-Code-Workflow%2Fspec-add%2F@5fd658d8d2d8dab54e449e47e9360632dae8fa4f