Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
warnThe skill contains instructions for the agent to potentially download and execute an external package ('getdesign') from an unverified source via npx, posing a risk of remote code execution. It also processes external, untrusted content like source code and screenshots, which creates an attack surface for indirect prompt injection.
Socket
passNo alerts
Snyk
passRisk: LOW · No issues