design-persona

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose, permissions, and data flows are mostly coherent for managing Coval personas, and it routes users to first-party Coval domains rather than an obvious intermediary. The main issue is install/execution trust: it relies on a `coval` CLI whose official distribution and release provenance were not verified in the provided evidence. That uncertainty is enough to raise risk, but there is not strong evidence of credential theft, exfiltration, or behavior fundamentally incompatible with the stated purpose.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Apr 14, 2026, 07:07 PM
Package URL
pkg:socket/skills-sh/coval-ai%2Fcoval-external-skills%2Fdesign-persona%2F@becf09080a36a1d4cc4e9e981bf0d390003da936