frontend

Warn

Audited by Socket on Jul 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS rather than malicious. The skill’s overall purpose is coherent for frontend/design work, but it widens the trust boundary through third-party tooling, external-content research, and instructions to load additional skills. No direct credential theft or attacker-controlled endpoint is shown, yet the combination of transitive skill loading and untrusted web content with execution/write capability makes this a medium-risk agent skill.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Jul 8, 2026, 05:05 PM
Package URL
pkg:socket/skills-sh/code-yeongyu%2Foh-my-opencode%2Ffrontend%2F@10807554d396455344ce19b5376c77e82e5344c5
Security Audit — socket — frontend