finalize

Warn

Audited by Socket on May 5, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is coherent for a UI audit skill, and it avoids code edits, credential requests, and explicit exfiltration. However, it executes an unpinned `npx` CLI that is not verified as an official publisher-controlled tool and also chains into another skill, making the trust boundary larger than the visible instructions suggest.

Confidence: 84%Severity: 74%
Audit Metadata
Analyzed At
May 5, 2026, 08:35 PM
Package URL
pkg:socket/skills-sh/educlopez%2Fui-craft%2Ffinalize%2F@6b70d2b6943d0f756a9936e7e9807c7e26fd6f9f