gsp-brand-identity

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core behavior mostly matches the stated purpose: reading local brand materials, asking structured user questions, generating identity docs, and orchestrating related design skills. However, the footprint is broader than necessary for a branding phase because it has Bash/Web access and delegates substantial work to multiple unseen downstream skills, creating transitive trust risk. No direct credential harvesting, hidden exfiltration, or malicious mismatch is present in this skill text, so this is not malware; the main concern is moderate execution and supply-chain risk from opaque sub-skill orchestration and an unresolved external palette-service reference.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 11, 2026, 04:03 AM
Package URL
pkg:socket/skills-sh/jubscodes%2Fget-shit-pretty%2Fgsp-brand-identity%2F@6470a1485a3d0c6205641c07d10f7b1777e3a78f