frontend-lp
Audited by Socket on Mar 11, 2026
1 alert found:
Obfuscated FileOverall, the skill's stated purpose (docs-first landing page development) is coherent, and many security properties are acceptable for a tooling guide. However, the explicit use of direct URL-based installs for Magic UI components and similar third-party assets constitutes a notable supply-chain risk. Without mandatory verification steps (checksum/signature validation, pinned versions, or registry-based installs) for those components, the risk elevates to suspicious. The data flow does not show credential or sensitive data leakage, but the install/flow pattern warrants caution. Recommend restricting to official registries or pinned, verifiable artifacts and adding integrity checks to reduce risk. Overall assessment: SUSPICIOUS (with actionable mitigations); not clearly malicious given the current description, but the footprint is larger than a typical docs-only guide and could be weaponized if misused.