openspec

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is benign and OpenSpec's own provenance looks legitimate, but the skill unnecessarily replaces the official direct npm/CLI path with the unrelated `x` launcher. That creates a disproportionate supply-chain trust expansion and download-execute risk, though there is no evidence here of credential theft or malicious data exfiltration.

Confidence: 90%Severity: 72%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:43 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fopenspec%2F@08562873be9c12eefdd0a0dfae643edc0fd62113