agent-ui
Warn
Audited by Socket on Mar 8, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill’s stated purpose (a batteries-included agent UI component with runtime, tools, streaming, approvals, and widgets) is generally coherent with its capabilities. However, there are notable security concerns around distribution (external URL-based install manifest), potential exposure of API credentials in client-side contexts, and data flow risk if the proxy/server separation is not strictly enforced. This warrants a SUSPICIOUS assessment due to supply-chain and credential-handling considerations, though it is not evidently malicious based on the provided material alone.
Confidence: 98%Severity: 55%
Audit Metadata