extract-design

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the core capability matches the stated purpose and the npm install path appears official, but the skill goes beyond simple design analysis by emphasizing anti-bot evasion and competitor reverse-engineering on arbitrary websites. No clear credential harvesting or malicious exfiltration is described, so this is not malware, but it carries medium security risk due to broad web access and stealthy browsing behavior.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 02:02 PM
Package URL
pkg:socket/skills-sh/dembrandt%2Fdembrandt-skills%2Fextract-design%2F@f536a730b0a44f47a7491b4b55e2f7b0ffc97a03