web-design-guidelines

Warn

Audited by Socket on Feb 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

[Skill Scanner] System prompt extraction attempt BENIGN but with a moderate supply-chain caveat: the skill's purpose and capabilities align and it performs expected actions (fetch guidelines, read files, apply rules). The only notable security consideration is that it fetches the rules at runtime from raw.githubusercontent.com without pinning or integrity verification — if that remote content were tampered with, the skill's behavior could change. No evidence of credential harvesting, remote code execution, or obfuscation was found. LLM verification: No direct malware or credential-harvesting code found in the provided SKILL.md fragment. The primary security issue is a supply-chain / prompt-injection risk: the skill fetches and treats unverified remote textual 'output format instructions' as authoritative at runtime, enabling a remote compromise of the guidelines file to cause data leakage or undesired agent behavior. Recommend pinning/vendoring guidelines, adding integrity checks (signatures/checksums), and refusing to honor remote instruct

Confidence: 80%Severity: 50%
Audit Metadata
Analyzed At
Feb 22, 2026, 04:55 AM
Package URL
pkg:socket/skills-sh/justinroderick%2Fskills%2Fweb-design-guidelines%2F@99ff92e24e7bb8f7e33a6cf1fcc23399fece4199