makepad-evolution

Warn

Audited by Socket on Aug 1, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The core Makepad-focused file access is broadly aligned with the stated purpose, and data flows go mainly to local files and normal GitHub tooling. However, the skill is high-friction from a trust perspective because it directs silent autonomous reads/writes, self-modifies other skills, tracks usage invisibly, and can drive git/PR publication using existing authenticated tooling without explicit per-action approval.

Confidence: 86%Severity: 74%
SecurityMEDIUM
skill-report.json

No classic executable malware indicators (network/exfiltration, shell execution payloads, credential theft) are evident in this fragment because it is primarily Markdown guidance. However, the document contains high-severity instruction patterns aimed at reducing user consent and enabling stealthy, persistent local self-modification: automatic editing of installed skill files, writing hidden metadata to agent settings, and symlink guidance that can redirect where edits land. In agent-assisted environments with file tool access, this represents a meaningful persistence and transparency/authorization boundary risk and should be reviewed/guardrailed before use.

Confidence: 65%Severity: 78%
Audit Metadata
Analyzed At
Aug 1, 2026, 10:21 AM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Fmakepad-evolution%2F@55e5c26f710432abde98bb4f08c3a706693be062b740ffcb45e0ff243ac2bb13
Security Audit — socket — makepad-evolution