ui-skills-root
Warn
Audited by Socket on Jun 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose matches a skill router, but it is primarily a transitive skill loader that pulls external instruction content through a CLI. No clear credential theft or direct exfiltration is shown, yet the external trust chain and remote instruction-loading make this medium risk.
Confidence: 100%Severity: 60%
Audit Metadata