penpot-workflow
Warn
Audited by Socket on May 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s design-management purpose is coherent, but trust and data-flow details are not. Its main concern is routing shared design content through an unofficial-looking `penpot.e9n.dev` host and relying on an unverifiable `pi-penpot` extension. The permissions and actions are otherwise broadly proportional to design work, so this looks more like medium/high security risk than confirmed malware.
Confidence: 82%Severity: 72%
Audit Metadata