pdf-design

Warn

Audited by Socket on Jun 18, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core PDF design/generation features are coherent with the stated purpose, and the external upload target is official Google Drive rather than a credential-harvesting proxy. However, the skill reads a raw local OAuth token file, uses hardcoded user-specific paths/folder IDs, and references an unverifiable local helper script, making the credential handling and execution trust broader than necessary for a simple PDF design workflow.

Confidence: 86%Severity: 52%
Audit Metadata
Analyzed At
Jun 18, 2026, 07:59 PM
Package URL
pkg:socket/skills-sh/jamditis%2Ftools%2Fpdf-design%2F@1d32f6b112b32ac816006c55b626fe92b9a82c48939422213c28b125e6689b25
Security Audit — socket — pdf-design