OpenDesign's community-growth campaign across GitHub, Discord, and X: the loops, the content calendar, and the pipeline math. Built as a decision-grade marketing & GTM deck for growth team, community lead.
57
72%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
High
Do not use without reviewing
Fix and improve this skill with Tessl
tessl review fix ./design-templates/html-ppt-zhangzara-coral/SKILL.mdDetected sensitive credentials directly embedded within the skill content, such as API keys, access tokens, private keys, or service-specific secrets. Secrets should never be hardcoded in plain text within skill instructions.
I scanned the skill files for literal high-entropy credentials (API keys, private keys, tokens). The only literal that looks like a usable access token is the Discord invite code "QHBCCH8AM4" embedded in the invite URL (DISCORD.GG/QHBCCH8AM4). A Discord invite code can grant access to a server and is not a generic placeholder or obviously fake/example text, so I treat it as a potential real credential. No API keys, RSA/PEM blocks, or other high-entropy secrets were found. Other values (GitHub repo URL, social handles, CDN/font links, example numbers/text) are not secrets.
The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.
The skill's HTML loads and executes remote JavaScript at runtime from https://cdn.jsdelivr.net/npm/chart.js@4.4.7/dist/chart.umd.min.js (Chart.js) which is a runtime-executed external dependency used to render the chart and thus executes remote code in the agent's runtime.
53231d4
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.