budge
Audited by Socket on May 30, 2026
2 alerts found:
AnomalySecurityThe provided module is an integration guide/snippet that loads a third-party CDN-hosted IIFE into multiple frameworks without showing SRI/version pinning or isolation controls. While the fragment itself shows no explicit malicious logic, it introduces a significant supply-chain trust boundary: the remotely served JavaScript can observe and modify the DOM and potentially consume embedded JSON configuration. The main actionable concern is integrity/provenance and containment of that external script.
SUSPICIOUS. The skill’s stated purpose mostly matches its file-edit behavior, and it does not request credentials or route data through explicit third-party APIs. However, its core functionality depends on loading an unpinned, unverifiable remote IIFE from budge.design into the app, which creates a high supply-chain trust problem for a narrowly scoped styling assistant.