ui-widget-developer
Warn
Audited by Socket on Jun 22, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is largely coherent for Copilot MCP/widget development, but it meaningfully expands trust and execution scope through automatic package/tool installs, public devtunnel exposure, detached process management, and especially transitive plugin/skill installation from an external marketplace. This looks more like a high-risk developer automation skill than malware.
Confidence: 89%Severity: 63%
Audit Metadata