agent-ui

Warn

Audited by Socket on May 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core purpose is coherent, and the API key/proxy flow generally matches an agent UI product. However, the skill expands trust through remote registry code installation and explicit transitive skill installation, with an unverifed `belt-sh/cli` path not clearly documented as the official install route. Risk is driven more by supply-chain and transitive trust than by confirmed malicious behavior.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
May 14, 2026, 02:28 AM
Package URL
pkg:socket/skills-sh/inference-sh-skills%2Fskills%2Fagent-ui%2F@efe9654736df3e0aebd60df9c0c64b6d0ee4adf2