design-ui
Warn
Audited by Socket on Apr 9, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the stated purpose is coherent for a design-skill router, but the auto-install behavior is disproportionate because it silently extends the agent with a remote third-party skill bundle. The main risk is transitive installation and supply-chain trust, not confirmed malware or exfiltration.
Confidence: 89%Severity: 74%
Audit Metadata