design-shotgun

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core design-variant workflow is plausible, but this skill is wrapped in a much broader gstack control plane that adds telemetry, artifact sync, local binary trust, browser/server actions, and optional git/CLAUDE.md mutations beyond the stated purpose. I do not see confirmed credential theft or clear malware, but the scope is disproportionate enough to rate as medium-high security risk.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
May 16, 2026, 06:26 PM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fdesign-shotgun%2F@82e80ddd0541ae28efa59c130fb81ebc7216d06b
Security Audit — socket — design-shotgun