design-tokens

Warn

Audited by Socket on Aug 8, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS: the local design-token core is coherent and mostly benign, but the skill’s footprint expands into external prompt/image generation, browser serving, and optional third-party API/script use. The main concerns are unspecified downstream skill-script trust and moderate autonomous external actions, not clear malware or credential theft.

Confidence: 81%Severity: 53%
AnomalyLOW
scripts/dtokens/generate.py

No clear evidence of embedded malware in this fragment (no network exfiltration, credential theft, or obfuscated payloads). However, it is security-relevant orchestration code: it executes local Python scripts from hardcoded ~/ .claude/skills/... paths without integrity checks and passes manifest-derived reference file paths and generated prompt text to those scripts. If the referenced scripts or manifest inputs are tampered with, an attacker can influence what external code runs and what files the external scripts access. Treat this as a potentially risky execution dispatcher rather than a self-contained safe library.

Confidence: 66%Severity: 62%
Audit Metadata
Analyzed At
Aug 8, 2026, 12:01 AM
Package URL
pkg:socket/skills-sh/glebis%2Fclaude-skills%2Fdesign-tokens%2F@02aa1b99b7b416dcd8e2ad9627061d271175297aeb51afaa2083d2b6911aad50
Security Audit — socket — design-tokens