design-spec-extraction

Warn

Audited by Socket on Feb 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The provided fragment is a coherent, file-based orchestration specification for a seven-pass design-spec extraction workflow. It is aligned with its stated purpose of extracting design tokens and components from visual sources and persisting intermediate/ final outputs for validation. There are no evident malicious behaviors, credential exposures, or external data flows within the fragment. The risk profile is low-to-moderate due to the potential for misconfiguration in an automated environment, but the content itself is not inherently dangerous. Treat as suspicious only if the execution environment permits unsafe file writes or introduces untrusted prompts that could modify passes; otherwise, it remains benign.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 27, 2026, 08:50 AM
Package URL
pkg:socket/skills-sh/Cygnusfear%2Fclaude-stuff%2Fdesign-spec-extraction%2F@545d2fa2a0184758e3c2a114ffbf9a8be8c4d7cb