speckit-specify

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The Speckit Specify skill’s footprint is coherent with its stated purpose: it generates feature specifications from natural language input, creates branch names, writes SPEC.md files, and produces a quality checklist, all within a local/project-context workflow. There are no credential requirements, no external data exfiltration, and no run-time downloads of unverified binaries. The risk profile is Benign with low-security concerns. Minor risks pertain to error handling around the external script invocation, but these do not imply security compromise. Overall, this skill is proportionate to its purpose and presents minimal security risk.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 12:18 PM
Package URL
pkg:socket/skills-sh/h3y6e%2Fspeckit-skills%2Fspeckit-specify%2F@d6c53c5b8564b675fc153ac0d2d8cc93954b84d7