agent-ui

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The fragment describes a battery-included agent UI component for React/Next.js with a proxy-based architecture and optional client-side tools. Security concerns center on remote installation from an external URL, potential exposure of API keys in client contexts, and data flows via the proxy that require strong access controls and data minimization. Not inherently malicious, but requires rigorous artifact verification, proper secret management (server-side only), CSP and network controls, and explicit data-flow boundaries. Recommend treating as Suspicious/Needs-Review pending artifact signing, secret isolation, and hardened proxy implementation.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Mar 4, 2026, 08:55 AM
Package URL
pkg:socket/skills-sh/1nfsh%2Fskills%2Fagent-ui%2F@2266185b2981f069769e162ab95b136ed61c1af3
Security Audit — socket — agent-ui