vueuse-functions

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected All findings: [CRITICAL] command_injection: Natural language instruction to download and install from URL detected (CI009) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] Benign: The skill fragment is a coherent, documentation-based guide for selecting and using VueUse composables. There are no indicators of malicious behavior, credential handling, or data exfiltration. The footprint aligns with its stated purpose as a reference/guidance resource rather than an executable tool. LLM verification: The fragment is largely aligned with its stated purpose of guiding VueUse usage. The primary concern is the presence of references to external download/installation resources within the static document, which could enable unsafe runtime behavior if exploited. Absent explicit, sandboxed, and user-consented procedures for external fetches, treat the external links pattern as a supply-chain risk. Recommend restricting the fragment to self-contained guidance and removing or clearly gating any extern

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 12:37 AM
Package URL
pkg:socket/skills-sh/andrianbalanescu%2Fskills%2Fvueuse-functions%2F@18c04491ad341afd9b49db5b3c2e67b0b128839b