design-swarm

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core design-review purpose is coherent, but the skill’s actual footprint is broader than a simple design helper: it transitively loads many other local skills from mixed, partially unverifiable locations and processes untrusted external content while retaining implementation capability. No clear credential theft or malicious exfiltration is present, but the transitive trust chain and prompt-injection-to-action path create meaningful security risk.

Confidence: 86%Severity: 74%
Audit Metadata
Analyzed At
May 14, 2026, 09:49 PM
Package URL
pkg:socket/skills-sh/SZoloth%2Fskill-pack%2Fdesign-swarm%2F@507a86a5b5ed96646c4b45b59350d1fbd20eec63
Security Audit — socket — design-swarm