pdf-design

Warn

Audited by Socket on Mar 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core PDF design/generation features are coherent with the stated purpose, and the external upload target is official Google Drive rather than a credential-harvesting proxy. However, the skill reads a raw local OAuth token file, uses hardcoded user-specific paths/folder IDs, and references an unverifiable local helper script, making the credential handling and execution trust broader than necessary for a simple PDF design workflow.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Mar 14, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/jamditis%2Fclaude-skills-journalism%2Fpdf-design%2F@83344de7eacc965cea6e40664e281e983969691b