ui-to-vue

Warn

Audited by Socket on Jun 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is coherent, but its core function depends on a not-clearly-verified third-party npm CLI that likely receives both design files and a DashScope API key. There is no obvious malicious behavior or deceptive endpoint in the text, yet install trust and credential/data forwarding are only partially verified, so the risk is medium rather than benign.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 16, 2026, 02:48 PM
Package URL
pkg:socket/skills-sh/affaan-m%2FECC%2Fui-to-vue%2F@69a21f1a60eec1e19f276b30e12200647d978842e217a93f662c17473e386d75
Security Audit — socket — ui-to-vue