ui-to-vue

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill's purpose is coherent, but its core function depends on a not-clearly-verified third-party npm CLI that likely receives both design files and a DashScope API key. There is no obvious malicious behavior or deceptive endpoint in the text, yet install trust and credential/data forwarding are only partially verified, so the risk is medium rather than benign.

Confidence: 84%Severity: 63%
Audit Metadata
Analyzed At
May 14, 2026, 10:52 AM
Package URL
pkg:socket/skills-sh/affaan-m%2Feverything-claude-code%2Fui-to-vue%2F@56b9c05bc137dd8c818e02eebce5220136d1ad17