brand-yml

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The fragment is coherently aligned with its stated purpose: a branding YAML generator for Quarto. It uses standard data gathering, validation against a spec, and YAML assembly without hidden or risky behaviors. No credentials, exfiltration, or autonomous actions are evident. The main risk is typical: pulling fonts/colors from the web could introduce inaccuracies if sources are untrusted, but this is expected behavior for a branding tool and not malicious per se.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 03:41 AM
Package URL
pkg:socket/skills-sh/stephenturner%2Fskill-brand-yml%2Fbrand-yml%2F@91cf4dcb1ab9e3a255af293ff021a765a67f7d51