ui-skills

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the visible catalog entry is benign on its face and aligned with a UI-guidance purpose, but it mainly serves as a pointer to install a transitive upstream skill from a personal GitHub repo. The biggest risk is supply-chain and inherited permissions from the unpinned upstream bundle, not confirmed malicious behavior in the provided entry itself.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fui-skills%2F@a9c12c4789ea1844a8d8296c9ef81267f64dccd03fd2dee34c6c02a2111f3b85
Security Audit — socket — ui-skills