generate-mockups
Warn
Audited by Socket on Sep 3, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The core capability fits the stated purpose, and the skill does not seek credentials or exfiltrate data, but it does expand trust by invoking other skills and by using an unpinned `npx`-fetched external CLI for advisory content. This is a coherent mockup skill with moderate supply-chain and transitive-trust risk rather than malware.
Confidence: 86%Severity: 54%
Audit Metadata