find-designs

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, and its network endpoints point to the stated vendor, but it instructs the agent to fetch and then follow a remote SKILL.md from Commons, creating a transitive trust chain and prompt-injection path with local file-write effects. Telemetry is limited and proportionate, and there is no obvious credential harvesting or malicious exfiltration, so this is not confirmed malware; the main issue is remote instruction execution disguised as design application.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Mar 19, 2026, 08:26 AM
Package URL
pkg:socket/skills-sh/heyzgj%2Fcommons-skills%2Ffind-designs%2F@1cd973e6d77c94323a9f76f23cbcfc5ebaf66f64