surge-landing

Warn

Audited by Socket on Aug 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose is benign, but it relies on an undocumented, publicly unverifiable executable Python module (`surge_agent.uiux`) to perform its core workflow. That dependency is disproportionate to a markdown design helper and creates high install/execution trust risk, though there is no direct evidence of credential theft or confirmed malicious behavior in the skill text itself.

Confidence: 88%Severity: 82%
Audit Metadata
Analyzed At
Aug 15, 2026, 01:39 PM
Package URL
pkg:socket/skills-sh/tonone-ai%2Ftonone%2Fsurge-landing%2F@4bd42c495a3e4951569ebf032eced30dc26d71193714ea5be9a3859196463008
Security Audit — socket — surge-landing