srs-generation

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The SRS generation skill presents a coherent, self-contained document production workflow that operates entirely within the project filesystem (scanning, reading local PRD/template/checklist, and writing the final srs.md). This aligns well with its stated purpose of generating standards-compliant SRS documents and maintaining traceability to upstream PRDs. There is no clear evidence of external credential handling, network calls, or transitive installation of unknown tools, which reduces risk. The main risk would arise if future extensions introduce remote template sources, untrusted inputs, or credential exposure during clarification or RTM generation; in its current form, the footprint is largely benign and proportionate to its purpose.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 10:03 AM
Package URL
pkg:socket/skills-sh/tercel%2Fspec-forge%2Fsrs-generation%2F@6842cef7075a1b92e57f38ebddd7b2cd1547af3c