ui-to-vue

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the install path uses normal npm tooling with a pinned version. However, it relies on an externally installed converter that receives both sensitive design inputs and a DashScope API key, while publisher/source provenance for that package was not clearly verified. The flagged .config access appears documentation-related rather than malicious, so this is not confirmed malware, but it carries meaningful third-party trust and data-handling risk.

Confidence: 81%Severity: 61%
Audit Metadata
Analyzed At
Sep 12, 2026, 03:40 PM
Package URL
pkg:socket/skills-sh/eugene-ee%2Faffaan-m-ecc%2Fui-to-vue%2F@69a21f1a60eec1e19f276b30e12200647d978842e217a93f662c17473e386d75
Security Audit — socket — ui-to-vue