brand-design-md

Warn

Audited by Socket on Apr 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/getdesign-helper.mjs

The fuzzy matching and scoring logic appears benign and self-contained. However, this module contains a high-risk capability: it can execute `npx getdesign@latest` (including a Windows `cmd.exe /c` path) with caller-influenced arguments, enabling runtime download/execution from the npm registry and creating a substantial supply-chain threat. No explicit data theft/persistence is shown in the provided snippet, but the external runtime execution pattern warrants strict review and hardening (pin versions, remove runtime npx, and validate/allowlist args).

Confidence: 66%Severity: 80%
Audit Metadata
Analyzed At
Apr 19, 2026, 02:50 PM
Package URL
pkg:socket/skills-sh/bahayonghang%2Fmy-claude-code-settings%2Fbrand-design-md%2F@a68625191e2c2df41c53b4a8ad2905bbe5099c1d