system-design-visualizer-tool
Warn
Audited by Socket on May 17, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s functionality broadly matches its description, but the install and trust story is inconsistent: ara.so claims authorship while directing users to clone and run an unrelated personal GitHub repo, then place an OpenAI key into a browser-exposed Vite variable. Data flows to OpenAI are expected for image analysis, but the publisher mismatch and client-side credential handling make the overall skill high risk rather than benign.
Confidence: 91%Severity: 78%
Audit Metadata