design-spec

Warn

Audited by Socket on Apr 5, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The visible skill is mostly aligned with UI design-spec generation and shows no explicit credential theft or malicious exfiltration, but it is over-permissioned with Bash and relies on opaque internal sub-skills/workflows plus untrusted visual/external content routing. Main risks are transitive trust and indirect prompt injection rather than confirmed malware.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 5, 2026, 05:52 AM
Package URL
pkg:socket/skills-sh/duc01226%2Feasyplatform%2Fdesign-spec%2F@d5fcf11444f4f8ce4a6bfd6f171a037d298cfd7c