21st-dev-components

Warn

Audited by Socket on Mar 20, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's overall purpose is coherent, but Auto mode materially increases risk by combining arbitrary site crawling, external component/code retrieval, and direct repo modification without documented verification boundaries. This looks more like a high-risk automation pattern than confirmed malicious behavior; no credential harvesting or explicit exfiltration is present in the supplied text.

Confidence: 81%Severity: 69%
Audit Metadata
Analyzed At
Mar 20, 2026, 12:29 PM
Package URL
pkg:socket/skills-sh/JStaRFilms%2FVibeCode-Protocol-Suite%2F21st-dev-components%2F@a8edabddbfbe3c62f9bf9ab88ddc2aa5236a0a41