paper-design

Fail

Audited by Socket on Mar 21, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
references/workflow-patterns.md

The document is a specification for automating design→code sync between Paper and a codebase using a watcher that polls MCP and an external LLM (claude -p). It does not contain explicit malicious code, but it prescribes patterns that create significant supply-chain and data-exfiltration risk: invoking an external LLM with combined design+project context and writing outputs directly to the repository without human review or robust validation. Treat this as a security warning: implement strict authentication, sandboxing, output validation, human review gates, and CI signing before accepting generated changes into source control.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 21, 2026, 07:49 PM
Package URL
pkg:socket/skills-sh/tdimino%2Fclaude-code-minoan%2Fpaper-design%2F@1efeb6b2c6439e61bf0c11a61a0e2cb9fb925b8a