openspec-ff-change

Fail

Audited by Socket on Mar 7, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The openspec-ff-change skill appears coherent with its stated purpose: it automates fast-forward artifact generation using the openspec CLI, deriving a change name, scaffolding, and creating artifacts in dependency order. It relies on trusted CLI tooling and local file I/O with no credentials or external network calls described, which is proportionate and reasonable. Potential risks mainly hinge on where the openspec CLI is sourced from and ensuring idempotent artifact creation to avoid overwrites. Overall, the footprint is benign and aligned, with moderate trust considerations around the CLI source.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 7, 2026, 09:05 AM
Package URL
pkg:socket/skills-sh/xu-cell%2Fai-engineering-init%2Fopenspec-ff-change%2F@478c34d2e95a2b43028133dbfd259e3be16b1b70