typeui-cli

Warn

Audited by Socket on Apr 11, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose is coherent, but the skill's main behavior is to execute an external CLI and pull remote markdown into agent skill locations, creating transitive-trust and indirect prompt-injection risk. No clear credential theft or exfiltration is present, so this is not confirmed malware, but it carries meaningful supply-chain risk.

Confidence: 79%Severity: 63%
Audit Metadata
Analyzed At
Apr 11, 2026, 04:15 AM
Package URL
pkg:socket/skills-sh/bergside%2Ftypeui%2Ftypeui-cli%2F@a989a3eacbddf7d4ebfb184c0eb6b2edb05c423f