tech-design-writer

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, but it routes sensitive user documents and an auth token through an undocumented third-party bridge over plain HTTP instead of an official documented OpenCode API. That makes the data flow and trust model disproportionate for a document-writing skill, even though there is no confirmed malware or true command injection.

Confidence: 92%Severity: 79%
Audit Metadata
Analyzed At
Sep 14, 2026, 02:32 AM
Package URL
pkg:socket/skills-sh/vangong1999%2Fopenwriting-skills%2Ftech-design-writer%2F@66a811a7417320943e35eda06e83e9da59d3211b9857877ce4a71c4f83c1cc06
Security Audit — socket — tech-design-writer