svg-icon-craft

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill content is coherent with a legitimate icon-design system oriented around SVGs and a Vue integration. The footprint is proportionate to the stated purpose (icon design system, registry, and UI patterns) with normal tooling (SVGO) and no evident credential or data-exfiltration misuse. A noteworthy concern is the SVGO plugin that forces fills/strokes, which could impact fidelity if not carefully managed. The registry-based approach, if misused to inject raw SVG strings into a live DOM via v-html, could pose a minimal XSS risk in untrusted contexts; ensure proper sanitization or use safer rendering (e.g., declarative SVG components) in production. Overall risk is low to moderate with attention to artifact fidelity and rendering safety.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 03:02 AM
Package URL
pkg:socket/skills-sh/endlessblink%2Fflow-state%2Fsvg-icon-craft%2F@133baccb614146b0f5aca36fae398a5e22bc88ca
Security Audit — socket — svg-icon-craft