openspec-update

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is a documentation-like skill description outlining how to update OpenSpec configurations by running standard CLI commands. There are no hardcoded secrets, credential reads, or suspicious data flows. It references legitimate package manager usage (npm install -g) and standard project initialization steps. No network exfiltration, third-party payloads, or autonomous actions are demonstrated. Overall, the content is coherent with the stated purpose and exhibits benign risk characteristics. If executed, the commands themselves are conventional and depend on user-managed environments; no hidden or unintended data handling is implied.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 12:36 PM
Package URL
pkg:socket/skills-sh/partme-ai%2Fopenspec-skills%2Fopenspec-update%2F@3887d055820a9ae210a50f76826f7ac2d8fcd0ec