iblai-component

Warn

Audited by Socket on Apr 29, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: mostly coherent developer-tooling guidance for ibl.ai app scaffolding, but it expands trust to a local token file, a mutable raw GitHub download, and transitive skill installation via `iblai add mcp`. No clear evidence of deliberate credential theft or malicious data routing is present, but the trust and scope are broader than a simple component guide.

Confidence: 81%Severity: 58%
Audit Metadata
Analyzed At
Apr 29, 2026, 06:06 PM
Package URL
pkg:socket/skills-sh/iblai%2Fvibe%2Fiblai-component%2F@3537b8a95195fde1a2fe8d1415009c1fc23479ec