agent-ui

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is coherent, and the API key/proxy flow generally matches an agent UI product. However, the skill expands trust through remote registry code installation and explicit transitive skill installation, with an unverifed `belt-sh/cli` path not clearly documented as the official install route. Risk is driven more by supply-chain and transitive trust than by confirmed malicious behavior.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Jun 19, 2026, 02:15 AM
Package URL
pkg:socket/skills-sh/halt-catch-fire%2Fskills%2Fagent-ui%2F@0dd9af55f120cdbc4c0e6f3bf85e0c685718193fb182b7681e3005717d780d95
Security Audit — socket — agent-ui