architecture

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core mapping task is benign, but the skill's footprint is not well-contained: it combines broad web ingestion, file writes, autonomous publishing, and a high-risk credential handling pattern that exports a GitHub token into plaintext storage. The Mermaid CDN use is a moderate supply-chain concern; the stronger issue is disproportionate credential exposure and automatic push behavior.

Confidence: 90%Severity: 86%
Audit Metadata
Analyzed At
Mar 29, 2026, 02:16 AM
Package URL
pkg:socket/skills-sh/ggprompts%2Fhtmlstyleguides%2Farchitecture%2F@7a70b9eaeb97922dbd7a4e5a6e6b1d664102758c