wireframe

Warn

Audited by Socket on Aug 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s stated purpose and capabilities are mostly aligned: it acts as a wireframing dispatcher and does not request credentials or route data to off-platform endpoints. The main concern is transitive trust: it relies on loading a family of other skills and is distributed through a personal GitHub repo via an external Skills CLI, which broadens the attack surface without strong release verification. This is not confirmed malware, but it carries moderate security risk from supply-chain and skill-chaining behavior.

Confidence: 84%Severity: 52%
Audit Metadata
Analyzed At
Aug 8, 2026, 06:24 PM
Package URL
pkg:socket/skills-sh/jpoindexter%2Fwireframe-skills%2Fwireframe%2F@92090d5d4ec8a91d01e6f000b189d779493c63629c99a30ab375853c034e473e
Security Audit — socket — wireframe