full-page-screenshot

Warn

Audited by Socket on May 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The advertised purpose is coherent, and the visible data flow stays local to Chrome DevTools with no clear credential harvesting or external exfiltration. However, this skill is mainly a catalogue pointer that asks the agent/user to install an upstream third-party skill from a personal GitHub repo via unpinned transitive install methods, which creates moderate supply-chain and trust-chain risk disproportionate to a simple discovery entry.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
May 15, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Ffull-page-screenshot%2F@2bab38f013036084937132ef1330a2c5d869387a
Security Audit — socket — full-page-screenshot