open-design
Warn
Audited by Socket on Jun 2, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, and its repo sources appear official, but it imports unpinned remote markdown instructions from a mutable GitHub clone and turns them into agent workflow with write authority. That makes it more risky than a normal documentation skill, especially because stub entries can lead to further upstream installs.
Confidence: 87%Severity: 63%
Audit Metadata