tlc-spec-driven

Warn

Audited by Socket on Apr 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core capabilities fit its stated purpose as a planning/execution workflow, and there is no direct credential harvesting or obvious exfiltration. Risk comes from transitive skill installation guidance, external research sources that could inject malicious instructions, and the ability to write code/files and create commits; overall this is a coherent but moderately risky agent workflow skill rather than confirmed malware.

Confidence: 85%Severity: 56%
Audit Metadata
Analyzed At
Apr 1, 2026, 09:04 PM
Package URL
pkg:socket/skills-sh/tech-leads-club%2Fagent-skills%2Ftlc-spec-driven%2F@de6f7aaa27edbd4f017828942b46b7c45408513e