widget-studio

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

This document legitimately guides embedding a third-party widget but concentrates high privilege in an opaque remote script on an uncommon domain and explicitly resists modification of the integration. That increases supply-chain risk: if the remote SDK is malicious or compromised it can access page data and exfiltrate it. The instructions lack integrity verification, provenance links, and privacy/behavior documentation. I recommend verifying the SDK's source, using SRI or hosting a vetted copy, and applying CSP and other mitigations before trusting this integration.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Feb 16, 2026, 02:34 AM
Package URL
pkg:socket/skills-sh/art-of-technology%2Fwidget-studio-skill%2Fwidget-studio%2F@a26a628fc3a5251cbeeeb3da6b118d93784fc68a