spec-kitty-agent

Fail

Audited by Socket on Mar 12, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill’s stated goal of end-to-end Spec-Kitty lifecycle orchestration and cross-agent configuration synchronization is superficially coherent with its described commands and deployment steps. However, the combination of mandatory command execution, multi-environment plugin deployment, and propagation of local configurations introduces meaningful security and control risks (unverified data flows, potential supply-chain exposure, and broad system access). The footprint is Suspicious overall and warrants thorough vetting: require explicit per-action user prompts/approval, enforce strict version pinning and checksums for all CLI tools, ensure all plugins come from trusted registries with signed artifacts, and implement explicit data-flow controls to prevent inadvertent leakage of sensitive configuration data across agent boundaries.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 12, 2026, 07:46 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fspec-kitty-agent%2F@497d120ec463073b78778c87f3802499d7c16f6b