visual-brief

Warn

Audited by Socket on Sep 3, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent for local report publishing, and it includes sensible warnings about untrusted page input. The main issue is install/execution trust: it requires an unverified `visual-brief` executable with no official provenance in the skill, plus an out-of-sandbox persistent watcher and an opaque callback endpoint path. No clear credential harvesting or confirmed malicious exfiltration is shown, but the unverifiable CLI alone makes the skill high risk.

Confidence: 85%Severity: 74%
Audit Metadata
Analyzed At
Sep 3, 2026, 04:18 AM
Package URL
pkg:socket/skills-sh/pchalasani%2Fclaude-code-tools%2Fvisual-brief%2F@7603737ae319268fd48d920886386f838537b11d204fa67822ad8014e0ef43b8
Security Audit — socket — visual-brief