designlang-design-extract

Warn

Audited by Socket on Apr 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core website design-extraction purpose is plausible, but the skill expands trust in ways that are not fully proportionate: it forwards sensitive cookies/headers to third-party CLI code, processes arbitrary web content while writing project files, and instructs installation of another skill from a mismatched publisher. No confirmed exfiltration is shown, but the trust and data-flow model is risky.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
Apr 16, 2026, 03:15 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fdesignlang-design-extract%2F@410ea524c6ba6c9c55c507f1f40b0f3e85171b26