front-dev

Warn

Audited by Socket on May 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core frontend capabilities are coherent and mostly use official ecosystems, so this is not fundamentally malicious. However, the skill expands beyond a normal frontend guide by instructing installation of a separate third-party skill and by introducing an annotation/MCP workflow that feeds untrusted external content into the agent, creating medium supply-chain and prompt-injection risk.

Confidence: 91%Severity: 61%
Audit Metadata
Analyzed At
May 11, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/marsolab%2Fskills%2Ffront-dev%2F@0e960242ef2ddefddd13a9a35732b2ff8ce9378c