web-design-guidelines

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it delegates its actual review rules to live remote markdown fetched from a mutable GitHub raw URL each run. That creates a meaningful indirect prompt-injection and trust risk even without clear credential theft or malware behavior.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
Mar 26, 2026, 04:44 PM
Package URL
pkg:socket/skills-sh/involvex%2Faetheris%2Fweb-design-guidelines%2F@4f52d9474d3da4f7c813193aa7329c6efc055ec6