spec-init

Fail

Audited by Socket on Mar 3, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The spec is primarily benign scaffolding with appropriate idempotence and clear file templates. The dominant security concern is the optional npx-based skills installation and the practice of placing third-party skills into an auto-loaded directory without enforced vetting. That pattern introduces a significant supply-chain and runtime-trust risk: remote code can run during install or later when skills are loaded by agents. No direct malicious code is present in the spec itself, but the workflow it prescribes can enable malicious outcomes if the installed skills are compromised or unvetted. Recommend treating the npx install as high-risk, pinning/artifact-verifying installs, prompting manual review, and recommending install isolation.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 3, 2026, 07:23 AM
Package URL
pkg:socket/skills-sh/HHU3637kr%2Fskills%2Fspec-init%2F@5d48c3ccda3d240d43cea713e61d8a02b014b972