ccc-design

Warn

Audited by Socket on Apr 1, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
normalize/SKILL.md

SUSPICIOUS: the core normalization behavior is plausible and locally scoped, but the mandatory dependency on other externally sourced skills creates disproportionate transitive trust and supply-chain risk relative to this skill alone. No direct credential theft or exfiltration is present, so this is not confirmed malicious.

Confidence: 84%Severity: 64%
AnomalyLOW
typeset/SKILL.md

SUSPICIOUS. The typography purpose is benign and internally coherent, with no direct credential access or exfiltration in this file. The main risk is transitive trust: it mandates use of other skills and potentially an npx-based GitHub install path for teach-impeccable without pinning or provenance details, which makes the overall skill chain moderately risky despite a benign stated purpose.

Confidence: 84%Severity: 62%
AnomalyLOW
design-consultation/SKILL.md

SUSPICIOUS: the core design functionality is benign, but the skill is bundled with broad gstack platform behavior—telemetry, analytics, update checks, contributor logging, browser launching, and optional remote installer/setup steps. Those capabilities are only partly related to design consultation and make the skill's footprint larger than its stated purpose, though there is not enough evidence of confirmed malicious intent.

Confidence: 84%Severity: 68%
Audit Metadata
Analyzed At
Apr 1, 2026, 05:37 AM
Package URL
pkg:socket/skills-sh/KevinZai%2Fcc-commander%2Fccc-design%2F@f015533885df9a3cc8a936c5932f705fe0ec7b83
Security Audit — socket — ccc-design