ui-skills

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the visible catalog entry is benign on its face and aligned with a UI-guidance purpose, but it mainly serves as a pointer to install a transitive upstream skill from a personal GitHub repo. The biggest risk is supply-chain and inherited permissions from the unpinned upstream bundle, not confirmed malicious behavior in the provided entry itself.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
Aug 27, 2026, 03:38 AM
Package URL
pkg:socket/skills-sh/skeletorflet%2Fopencode-supreme-setup%2Fui-skills%2F@028645e711489b6f4e7927b51f98d1ff37fcd4f1f13cfc7d7c25aaf9a8017a1f
Security Audit — socket — ui-skills