excalidraw

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s functional scope is mostly coherent and proportionate for diagram generation, with no clear credential harvesting or malicious data exfiltration. However, the supporting installation/trust evidence points to third-party personal GitHub repos and mutable container tags rather than official Excalidraw distribution, so supply-chain trust is the main concern.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 11, 2026, 06:33 AM
Package URL
pkg:socket/skills-sh/edwingao28%2Fexcalidraw-toolkit%2Fexcalidraw%2F@fd181c78a3534f09d7ae33f834bfd98ff252c867