design-swarm
Warn
Audited by Socket on May 14, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core design-review purpose is coherent, but the skill’s actual footprint is broader than a simple design helper: it transitively loads many other local skills from mixed, partially unverifiable locations and processes untrusted external content while retaining implementation capability. No clear credential theft or malicious exfiltration is present, but the transitive trust chain and prompt-injection-to-action path create meaningful security risk.
Confidence: 86%Severity: 74%
Audit Metadata