system-design-visualizer-tool

Warn

Audited by Socket on May 17, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s functionality broadly matches its description, but the install and trust story is inconsistent: ara.so claims authorship while directing users to clone and run an unrelated personal GitHub repo, then place an OpenAI key into a browser-exposed Vite variable. Data flows to OpenAI are expected for image analysis, but the publisher mismatch and client-side credential handling make the overall skill high risk rather than benign.

Confidence: 91%Severity: 78%
Audit Metadata
Analyzed At
May 17, 2026, 06:51 PM
Package URL
pkg:socket/skills-sh/Aradotso%2Fdesign-skills%2Fsystem-design-visualizer-tool%2F@a9931b353c1d10aeacbc95c9566c22c1ec7b1c2a