design-review

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the catalog entry is not malicious on its face, but it mainly functions as a pointer that asks the user to install another upstream skill bundle and execute its setup. The main risk is transitive skill installation plus external setup execution; no direct credential harvesting or exfiltration is shown in this entry.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Sep 14, 2026, 03:43 PM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Fdesign-review%2F@d0368f4da012ac7a9986bdf0a5fc504196c6694f9f017e2b79dcad880be31ea4
Security Audit — socket — design-review