wix-vibe-headless

Warn

Audited by Socket on Sep 11, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
platforms/base44-ecom-light-seed-with-install.md

The fragment is an automation workflow with a significant supply-chain and privileged-execution risk: it downloads unpinned remote skill content via npx, executes its scripts, and uses a Wix bearer token for administrative seeding. No direct malicious payload or data exfiltration is shown in the supplied text, but the unseen downloaded modules and seed/deployment scripts must be independently reviewed and pinned before execution.

Confidence: 96%Severity: 72%
AnomalyLOW
platforms/base44-ecom-light.md

This fragment is a build/deployment orchestrator that conditionally installs three external Wix-related skills via `npx -y` and then executes local deployment/pinning scripts from the installed skill package. No explicit malicious behavior is evident in the snippet itself (no hardcoded credentials or obvious exfiltration), but it creates a meaningful supply-chain attack surface by downloading and executing third-party code at build time without visible version pinning or integrity verification. The risk level is therefore driven primarily by potential compromise of the referenced skills or their transitive dependencies.

Confidence: 58%Severity: 56%
Audit Metadata
Analyzed At
Sep 11, 2026, 11:30 AM
Package URL
pkg:socket/skills-sh/wix%2Fskills%2Fwix-vibe-headless%2F@1009cfbd0457872c45135e53e4ab5f21c7950c9f92057b1629a6c06af2610ca5
Security Audit — socket — wix-vibe-headless