frontend-lp

Fail

Audited by Socket on Mar 11, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill's stated purpose (docs-first landing page development) is coherent, and many security properties are acceptable for a tooling guide. However, the explicit use of direct URL-based installs for Magic UI components and similar third-party assets constitutes a notable supply-chain risk. Without mandatory verification steps (checksum/signature validation, pinned versions, or registry-based installs) for those components, the risk elevates to suspicious. The data flow does not show credential or sensitive data leakage, but the install/flow pattern warrants caution. Recommend restricting to official registries or pinned, verifiable artifacts and adding integrity checks to reduce risk. Overall assessment: SUSPICIOUS (with actionable mitigations); not clearly malicious given the current description, but the footprint is larger than a typical docs-only guide and could be weaponized if misused.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 11, 2026, 02:13 AM
Package URL
pkg:socket/skills-sh/petrogurcak%2Fskills%2Ffrontend-lp%2F@3077e46c9b4c54aef2d8977a5cf3260c701369af