design-describe

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core design-description behavior is benign, but the mandatory use of a third-party skill introduces transitive trust risk disproportionate to a simple screenshot-description task. No direct credential theft, exfiltration, or installer abuse is present in this file, so this looks more like a medium-risk vulnerable skill than malware.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Mar 27, 2026, 06:11 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fdesign-describe%2F@d85ba79a978ee07d549c06ecf6acdc8001e32e5e