designer
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The stated purpose is coherent, and file access is mostly proportionate for design review, but the broad Bash(npx*) permission materially expands the footprint beyond a typical critique skill. The main risk is arbitrary npm code execution and possible interaction with untrusted URLs; there is no clear evidence of credential theft, exfiltration, or malicious intent.
Confidence: 84%Severity: 58%
Audit Metadata