widgets-ui

Warn

Audited by Socket on May 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's purpose and examples are coherent for declarative UI rendering, and there is no sign of credential theft or malicious data routing. However, it includes transitive skill installation and unpinned remote registry installs, which increase supply-chain risk beyond what is strictly necessary for a widget-rendering guide.

Confidence: 87%Severity: 66%
Audit Metadata
Analyzed At
May 13, 2026, 01:13 PM
Package URL
pkg:socket/skills-sh/inference-sh%2Fskills%2Fwidgets-ui%2F@e87471db2bfe522f74dda2b9b65acb627e96f18f
Security Audit — socket — widgets-ui