execute-openspec-change
Fail
Audited by Socket on Mar 1, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The piece outlines a coherent OpenSpec-change orchestration blueprint with a clearly defined state machine and persistent state. It does not reveal direct malicious activity or exfiltration vectors in this fragment. However, the heavy reliance on multiple external skills and local state persistence presents elevated supply-chain and data-access risk. Recommend tightening trust boundaries, enforcing least-privilege for git/worktree actions, securing logs/state, and validating all external skill inputs before execution.
Confidence: 98%
Audit Metadata