ui-to-vue
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the install path uses normal npm tooling with a pinned version. However, it relies on an externally installed converter that receives both sensitive design inputs and a DashScope API key, while publisher/source provenance for that package was not clearly verified. The flagged .config access appears documentation-related rather than malicious, so this is not confirmed malware, but it carries meaningful third-party trust and data-handling risk.
Confidence: 81%Severity: 61%
Audit Metadata