diagram

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core diagram capability is legitimate and mostly offline, but this skill is bundled with a large gstack control plane that reads broad local state, writes analytics, may sync artifacts remotely, and can modify repo files and commits unrelated to making a diagram. Same-org provenance lowers malware confidence, but the scope is disproportionate to the skill's stated purpose.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 05:15 AM
Package URL
pkg:socket/skills-sh/garrytan%2Fgstack%2Fdiagram%2F@8feb6aff501071b17fb04293a85cd92432ef06868d6af4dfee519bec1c086c83
Security Audit — socket — diagram