design-taste-frontend

Warn

Audited by Socket on Aug 7, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's design purpose is benign, but its install instructions are inconsistent with the cited upstream project and rely on globally installing code from an unpinned third-party GitHub clone. No direct credential theft or exfiltration is shown, but install trust is weak enough to make the skill risky.

Confidence: 89%Severity: 72%
SecurityMEDIUM
scripts/ensure-ui.mjs

No direct indicators of overt malware (e.g., network exfiltration, credential theft, or persistence) are present in this snippet. However, the code’s core behavior—PowerShell-based extraction and subsequent detached execution of a bundled Windows .exe, with no integrity verification of the ZIP/exe—creates a significant supply-chain/execution risk if the packaged ZIP or executable is tampered with. This module should be treated as high-risk from an operational validation standpoint and reviewed/validated against expected, known-good artifacts (hash/signature checks, ZIP content constraints, and clearer execution/visibility expectations).

Confidence: 66%Severity: 72%
Audit Metadata
Analyzed At
Aug 7, 2026, 09:42 PM
Package URL
pkg:socket/skills-sh/0xwilliamortiz%2Ftaste-skill%2Fdesign-taste-frontend%2F@3ea1e48acd6eb6801e86530eb9ff33ac7b96b4d7cdf2dbc507d4ccad1ab42299
Security Audit — socket — design-taste-frontend