panda-css

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Credential file access detected Cannot assess malicious activity or security risk without the actual code. Request the panda-css.m content to proceed with a proper review and risk scoring. LLM verification: This SKILL.md fragment is suspicious and potentially dangerous because it instructs the agent to load a file from the user's ~/.config tree using a relative path traversal. Even though there is no explicit exfiltration code present, resolving and reading that dotfile could expose sensitive credentials or agent configuration via normal agent outputs or integrations. Recommend not running this skill as-is. Remediation options: embed required rules inside the skill or the repository, require explic

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/hashintel%2Fhash%2Fpanda-css%2F@1a16f0e839297b0840063f565f3e438139c1e041