pdf-design

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core PDF design and preview behavior is coherent, but the skill also reads a raw Google OAuth token from a hardcoded local path and can upload files to fixed Google Drive folders. Data flows go to official Google endpoints rather than a third-party proxy, so this is not confirmed malware, but the credential-file access and user-specific upload wiring make the skill higher risk than a normal local document-design tool.

Confidence: 85%Severity: 62%
Audit Metadata
Analyzed At
Apr 15, 2026, 07:58 PM
Package URL
pkg:socket/skills-sh/jamditis%2Fclaude-skills-journalism%2Fpdf-design%2F@20c30bf26127d702119ab7d2430a8d24ebc37376