spec-driven-development

Fail

Audited by Socket on Feb 21, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Code execution from unpinned remote source (uvx/pipx + git URL) Benign documentation artifact with clear guidance on Spec-Driven Development using GitHub spec-kit. Primary risk is reliance on external tooling for execution, which is standard for OSS workflow tools. No malicious behavior detected within the fragment itself. LLM verification: This SKILL.md is primarily documentation for using GitHub's spec-kit (specify CLI) and does not itself contain malicious code or direct data-exfiltration behavior. However, it instructs unpinned installation of a third-party CLI from a remote git URL and relies on runtime-installed agent configuration (.github/agents, .claude/) which can influence AI agent behavior. That download-and-execute pattern is a supply-chain risk: if the upstream repository or generated agent files are compromised, an a

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 21, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/vineethsoma%2Fagent-packages%2Fspec-driven-development%2F@676168df74c6050eca1e8c598f3716d238313a7d