interactive-widget

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities broadly align, but its core function depends on an externally hosted service and CLI whose publisher relationship and official provenance could not be verified. Data flows are consistent with widget hosting, yet permanent remote artifact upload plus opaque CLI trust make the overall risk medium-high rather than benign.

Confidence: 83%Severity: 72%
Audit Metadata
Analyzed At
Apr 10, 2026, 08:26 AM
Package URL
pkg:socket/skills-sh/aidgets%2Fduoduo-widgets%2Finteractive-widget%2F@04746a367bb8f53895d704c73eb1e6741767a7a1