design-tokens

Warn

Audited by Socket on Aug 10, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/dtokens/generate.py

No clear evidence of embedded malware in this fragment (no network exfiltration, credential theft, or obfuscated payloads). However, it is security-relevant orchestration code: it executes local Python scripts from hardcoded ~/ .claude/skills/... paths without integrity checks and passes manifest-derived reference file paths and generated prompt text to those scripts. If the referenced scripts or manifest inputs are tampered with, an attacker can influence what external code runs and what files the external scripts access. Treat this as a potentially risky execution dispatcher rather than a self-contained safe library.

Confidence: 66%Severity: 62%
Audit Metadata
Analyzed At
Aug 10, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/glebis%2Fhumane-agentic-design%2Fdesign-tokens%2F@0d7cdd7034c145db0a92933c1b1ef7068de204e0467356d4e751826fe742500c
Security Audit — socket — design-tokens