visual-brief
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent for local report publishing, and it includes sensible warnings about untrusted page input. The main issue is install/execution trust: it requires an unverified `visual-brief` executable with no official provenance in the skill, plus an out-of-sandbox persistent watcher and an opaque callback endpoint path. No clear credential harvesting or confirmed malicious exfiltration is shown, but the unverifiable CLI alone makes the skill high risk.
Confidence: 85%Severity: 74%
Audit Metadata