design-import
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the core purpose and capabilities are mostly aligned for a design-handoff import workflow, and the main remote source is the official claude.ai/design domain. The main risk is not overt malware but broad transitive trust plus indirect prompt injection: externally sourced bundle content is parsed and then used by subagents with write and bash access to modify the repo.
Confidence: 84%Severity: 58%
Audit Metadata