spec

Warn

Audited by Socket on Feb 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill fragment outlines a coherent, AI-assisted product-spec workflow with GitHub orchestration and external drafting/validation tools. It is capable but introduces notable operational autonomy risks (automatic issue creation, label updates, and spec drafting) that could be abused or misaligned without safeguards. To improve security and reliability, implement explicit per-action user confirmation for destructive steps, sandboxed external tool calls with strict input/output validation, robust authentication/audit logging, and configurable governance policies (e.g., disable auto-create skeletons in public repos). Overall, the approach is viable for controlled environments but requires strong guardrails to be safe in broader contexts.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 28, 2026, 04:49 AM
Package URL
pkg:socket/skills-sh/phrazzld%2Fclaude-config%2Fspec%2F@60235db7e2c2638fd18407688b5c6ac6379a0889