frontend
Warn
Audited by Socket on Jul 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS rather than malicious. The skill’s overall purpose is coherent for frontend/design work, but it widens the trust boundary through third-party tooling, external-content research, and instructions to load additional skills. No direct credential theft or attacker-controlled endpoint is shown, yet the combination of transitive skill loading and untrusted web content with execution/write capability makes this a medium-risk agent skill.
Confidence: 82%Severity: 58%
Audit Metadata