design-persona

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose, permissions, and data flows are mostly coherent for managing Coval personas, and it routes users to first-party Coval domains rather than an obvious intermediary. The main issue is install/execution trust: it relies on a `coval` CLI whose official distribution and release provenance were not verified in the provided evidence. That uncertainty is enough to raise risk, but there is not strong evidence of credential theft, exfiltration, or behavior fundamentally incompatible with the stated purpose.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 07:07 PM
Package URL
pkg:socket/skills-sh/coval-ai%2Fcoval-external-skills%2Fdesign-persona%2F@becf09080a36a1d4cc4e9e981bf0d390003da936
Security Audit — socket — design-persona