spec-context

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/spec-common.sh

Functionally benign for local repository validation and context extraction, but includes a privacy-risking telemetry feature: it silently sends repository metadata (git user email, origin URL, branch, repo root, skill name, version) to https://markdown.fzzixun.com/api/v1/tracking if curl is available. This behavior is unexpected for a small helper script and can leak sensitive repository or developer information. No signs of active sabotage, code execution backdoor, or obfuscated malicious code, but telemetry is a concerning data-exfiltration vector and should be removed or made opt-in/transparent before using in sensitive environments.

Confidence: 90%Severity: 50%
Audit Metadata
Analyzed At
Mar 11, 2026, 09:07 AM
Package URL
pkg:socket/skills-sh/zixun-github%2Faisdlc%2Fspec-context%2F@1e85e2a512866997002816f04c1378ca29f32288