spec-kitty-sync-plugin

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent with a Spec-Kitty maintenance skill, but it has notable internal inconsistencies and a meaningful transitive-install risk. The official PyPI install path lowers concern, yet the misleading dependency claims, incorrect Python requirement, and ability to install all plugins into agent environments make the footprint broader and riskier than the description suggests.

Confidence: 85%Severity: 63%
Audit Metadata
Analyzed At
Apr 27, 2026, 08:40 AM
Package URL
pkg:socket/skills-sh/richfrem%2Fagent-plugins-skills%2Fspec-kitty-sync-plugin%2F@68afa83882f7133064963f3f726be7b55c57e235