CtrlK
BlogDocsLog inGet started
Tessl Logo

od-contribute

One-click contribution flow for OpenDesign (nexu-io/open-design) — even for non-coders. Pick one of four cards (ship a Skill or Design System you made with OD; translate docs; fix a typo / write a blog; report a bug), the agent validates and opens a PR (or issue) for you. Trigger words contribute to open design, ship my OD skill, ship my OD design system, translate OD docs, report an OD bug, od-contribute.

Invalid
This skill can't be scored yet
Validation errors are blocking scoring. Review and fix them to unlock Quality, Impact and Security scores. See what needs fixing →
SKILL.md
Quality
Evals
Security
Critical

E005: Suspicious download URL detected in skill instructions.

What this means

Detected a suspicious URL in the skill instructions that could lead the agent to download and execute malicious scripts or binaries. This includes links to executables from untrusted sources, typosquatting of official packages, URL shorteners that obscure the destination, and personal file hosting services.

Why it was flagged

The list includes a direct raw.githubusercontent.com link to an install.sh (and the script itself documents running it via curl | bash), which is a high-risk pattern for distributing malware even when hosted on GitHub.

Report incorrect finding
High

W007: Insecure credential handling detected in skill instructions.

What this means

The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.

Why it was flagged

The skill tells the agent to substitute {{DISCORD_INVITE}} from the environment variable $OD_DISCORD_INVITE into rendered PR/issue bodies and then preview the rendered PR (head -40), which forces the agent to read and output an env-held value verbatim; it also instructs surfacing install/auth hints verbatim.

Low

W012: Unverifiable external dependency detected (runtime URL that controls agent).

What this means

The skill fetches instructions or code from an external URL at runtime, and the fetched content directly controls the agent’s prompts or executes code. This dynamic dependency allows the external source to modify the agent’s behavior without any changes to the skill itself.

Why it was flagged

The skill's installer suggests running a curl|bash one-liner that would execute remote code from https://raw.githubusercontent.com/nexu-io/open-design/main/.claude/skills/od-contribute/install.sh (and that install.sh itself fetches a tarball from https://github.com/${REPO}/archive/refs/heads/${BRANCH}.tar.gz), so remote content would be fetched and executed at runtime.

Repository
nexu-io/open-design
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.