pdf-design
Warn
Audited by Socket on Jul 21, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. Most PDF generation behavior is coherent and uses official tools, but the skill also reads a raw local Google OAuth token and uploads files externally, which is a notable scope expansion. The custom local preview script has unverifiable provenance, raising install/execution trust risk, though there is no clear evidence of credential theft or attacker-controlled endpoints.
Confidence: 88%Severity: 71%
Audit Metadata