huashu-design-html-native

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The design/export capabilities are mostly coherent with the stated purpose, and there is no clear credential theft or exfiltration path. The main concern is install trust: the skill is distributed via transitive skill installation from a source that does not clearly match the claimed publisher, which is disproportionate supply-chain risk for an otherwise benign design tool.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Apr 21, 2026, 07:43 AM
Package URL
pkg:socket/skills-sh/Aradotso%2Ftrending-skills%2Fhuashu-design-html-native%2F@1bb813b22a16145dceb3b2ed75ee00d625abb1cb