w-v0

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is plausible, but it routes prompt content from local files to w-v0.dev rather than an official Vercel v0 endpoint. With no evidence that w-v0.dev is operated by Vercel, the main risk is unintended disclosure of repo/context data to an unrelated third party.

Confidence: 90%Severity: 74%
Audit Metadata
Analyzed At
Sep 18, 2026, 01:00 AM
Package URL
pkg:socket/skills-sh/blockmatic%2Fbasilic-skills%2Fw-v0%2F@17b401b13736db9194741107efeeaba3a0acb1acd7c46f3e1e3882244ebeafd1
Security Audit — socket — w-v0