ui-design

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it routes image generation through ZenMux rather than the official OpenAI API and may read credentials from local files before forwarding them to that third party. The main risk is intermediary data exposure plus limited provenance for the unseen local script, not confirmed malware.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:25 AM
Package URL
pkg:socket/skills-sh/oil-oil%2Fdraw-ui%2Fui-design%2F@9bfb1c54506ab52da3009c1f9f306da9cacb359c