spets

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose fits workflow orchestration, but the skill hands broad control to a remotely executed npm package and then blindly follows its JSON instructions. The main risk is not the SDD concept itself; it is the combination of unpinned `npx` execution, recursive remote instruction following, and data flowing back through orchestrator-controlled callbacks.

Confidence: 87%Severity: 82%
Audit Metadata
Analyzed At
Apr 8, 2026, 11:03 AM
Package URL
pkg:socket/skills-sh/team-attention%2Fcode-squad%2Fspets%2F@5a4d8e65cb2c5cbedea71b04b5e0c6e923b360b7