ui-to-vue

Warn

Audited by Socket on Sep 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities mostly align, but the core dependency is an external npm CLI whose official ownership and provenance were not verified, and it receives both API credentials and potentially sensitive screenshots for external processing. This is not confirmed malware, but it carries meaningful supply-chain and data-exposure risk.

Confidence: 79%Severity: 58%
Audit Metadata
Analyzed At
Sep 1, 2026, 02:38 AM
Package URL
pkg:socket/skills-sh/defuj%2Fopencode-agent-kit%2Fui-to-vue%2F@04f417523c655adef5aa3af09cc1977f2a05c036854b29a04d4dd1829bab74e4
Security Audit — socket — ui-to-vue