budge

Warn

Audited by Socket on May 30, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
references/INSTALL.md

The provided module is an integration guide/snippet that loads a third-party CDN-hosted IIFE into multiple frameworks without showing SRI/version pinning or isolation controls. While the fragment itself shows no explicit malicious logic, it introduces a significant supply-chain trust boundary: the remotely served JavaScript can observe and modify the DOM and potentially consume embedded JSON configuration. The main actionable concern is integrity/provenance and containment of that external script.

Confidence: 60%Severity: 66%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose mostly matches its file-edit behavior, and it does not request credentials or route data through explicit third-party APIs. However, its core functionality depends on loading an unpinned, unverifiable remote IIFE from budge.design into the app, which creates a high supply-chain trust problem for a narrowly scoped styling assistant.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
May 30, 2026, 01:08 AM
Package URL
pkg:socket/skills-sh/ben-million%2Fskills%2Fbudge%2F@9bd558ed599edf94cab0f922b240b0cf7b1626d0
Security Audit — socket — budge