widgets-ui
Warn
Audited by Socket on Jul 23, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the core widget-rendering purpose is coherent, and the ui.inference.sh component source appears same-org and proportionate. However, the separate belt-sh/cli skill install is not clearly needed for this skill and creates avoidable cross-skill, cross-publisher trust expansion; combined with explicit transitive skill installation instructions, this raises medium-high security risk despite no direct credential theft behavior.
Confidence: 87%Severity: 71%
Audit Metadata