claude-design-system-hooks
Warn
Audited by Socket on May 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The stated purpose is plausible, but the actual footprint is not internally trustworthy: a personal GitHub repo advertises Claude-branded packages and images with no verifiable official release trail, then asks users to forward multiple API tokens into that toolchain and install community extensions. This combination is inconsistent with a low-risk design helper and meets the mandatory high-risk floor for unverifiable binaries/CLIs receiving credentials.
Confidence: 92%Severity: 90%
Audit Metadata