quickdesign

Warn

Audited by Socket on Aug 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s media-generation behavior is broadly consistent with its stated purpose, but it depends on an unverifiable proprietary CLI that handles authentication and uploads user media to undisclosed backend services. That combination creates high supply-chain and credential-forwarding risk even though the visible instructions themselves are not overtly malicious.

Confidence: 82%Severity: 82%
Audit Metadata
Analyzed At
Aug 1, 2026, 04:47 AM
Package URL
pkg:socket/skills-sh/anthropics%2Fclaude-plugins-community%2Fquickdesign%2F@595bfcce4542bb7c5b9a22aac82557186645118e0210320f5537b518c3b93df8
Security Audit — socket — quickdesign