ds-inspection
Warn
Audited by Socket on Jul 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core inspection workflow is coherent and mostly documentation-like, but the skill blurs trust boundaries by encouraging use of any connected design-tool bridge and explicitly naming a third-party Figma MCP that can receive bearer tokens and design data outside official Figma endpoints. No direct malware behavior or installer is present, but data-flow and credential-forwarding risks are material.
Confidence: 88%Severity: 54%
Audit Metadata