spec-writer
Warn
Audited by Socket on Feb 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
The provided fragment describes a high-level workflow for an interactive spec-writing skill. It is coherent with its stated purpose (to generate activity specs via deep interviews) and does not exhibit any evident malicious behavior, credential handling, or supply-chain risks within the fragment itself. The design relies on user input and iterative questioning, with no apparent download, execution, or data exfiltration patterns. Overall, the footprint is benign and proportional to its stated purpose.
Confidence: 75%Severity: 75%
Audit Metadata