google-design

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core DESIGN.md functionality is coherent, but the installation story is not: a purported Google design-token skill also instructs installing a separate third-party skill from akillness/oh-my-skills. That transitive trust hop is unnecessary for the stated purpose and is the main security concern. Without independent verification of the npm package and official install paths, this should be treated as medium-high risk rather than benign.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
Apr 22, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Fgoogle-design%2F@3bb1ed42bf4980ecc75fb9e27f5447af447280ed