huashu-design-html-native
Warn
Audited by Socket on Apr 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The design/export capabilities are mostly coherent with the stated purpose, and there is no clear credential theft or exfiltration path. The main concern is install trust: the skill is distributed via transitive skill installation from a source that does not clearly match the claimed publisher, which is disproportionate supply-chain risk for an otherwise benign design tool.
Confidence: 85%Severity: 74%
Audit Metadata