agent-ui

Warn

Audited by Socket on Mar 8, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill’s stated purpose (a batteries-included agent UI component with runtime, tools, streaming, approvals, and widgets) is generally coherent with its capabilities. However, there are notable security concerns around distribution (external URL-based install manifest), potential exposure of API credentials in client-side contexts, and data flow risk if the proxy/server separation is not strictly enforced. This warrants a SUSPICIOUS assessment due to supply-chain and credential-handling considerations, though it is not evidently malicious based on the provided material alone.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Mar 8, 2026, 02:51 AM
Package URL
pkg:socket/skills-sh/1nfsh-s3%2Fskills%2Fagent-ui%2F@2266185b2981f069769e162ab95b136ed61c1af3