spec-kitty-agent

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities mostly align with a spec-driven dev workflow, and the primary CLI install source appears legitimate. The main concern is transitive trust: it installs/depends on additional skills and propagates configuration into agent environments, increasing the blast radius beyond a simple workflow helper. No clear credential theft or exfiltration is present, but the install-and-sync footprint is broader than a narrowly scoped local planning skill.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Mar 19, 2026, 09:03 PM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fspec-kitty-agent%2F@87ba7e36e94bb0ad9814a5b400ee8364ed082b8c