ai-spec

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided code fragment is a production-grade guidance/specification document intended to shape AI-driven software specification workflows. It does not perform any data processing, credential handling, or network activity within the fragment itself. As such, it poses minimal operational security risk in isolation and is coherent with its stated purpose of generating structured technical specs and executable AI instructions. However, if this specification were to be instantiated by an agent that automatically executes the described steps (e.g., running npm install, invoking lint, or deploying docs), then supply-chain and data-flow risks would hinge on the actual executed tooling and environment. In its current form, the footprint is benign and aligned with its stated purpose.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:06 PM
Package URL
pkg:socket/skills-sh/hhx465453939%2FClaude_skill_pool%2Fai-spec%2F@9cdfdab409600afc47ceeb37389a412fea361289