ui-widget-developer

Warn

Audited by Socket on Jun 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill is largely coherent for Copilot MCP/widget development, but it meaningfully expands trust and execution scope through automatic package/tool installs, public devtunnel exposure, detached process management, and especially transitive plugin/skill installation from an external marketplace. This looks more like a high-risk developer automation skill than malware.

Confidence: 89%Severity: 63%
Audit Metadata
Analyzed At
Jun 22, 2026, 11:52 AM
Package URL
pkg:socket/skills-sh/microsoft%2Fskills%2Fui-widget-developer%2F@fc2a83fea3fe0c3f283f5a0dceb24f0a4781448220054b9578c774f81ab87aec
Security Audit — socket — ui-widget-developer