frontend-dev

Warn

Audited by Socket on Jun 12, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the entry is mostly benign as a catalogue pointer, but its real effect is to steer the agent/user into installing an upstream skill bundle, creating transitive trust and mutable repo-based supply-chain risk. No direct credential theft or malicious execution appears in this file alone, but the install indirection is disproportionate to a simple discovery entry.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 12, 2026, 09:01 PM
Package URL
pkg:socket/skills-sh/nexu-io%2Fopen-design%2Ffrontend-dev%2F@22d477428f8798ae2bc8a24c33d1b17e0ffdf739
Security Audit — socket — frontend-dev