use-topbar

Warn

Audited by Socket on Apr 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core UI-scaffolding purpose mostly matches the file reads/writes and theme wiring, and the shadcn CLI path appears official. However, the skill adds persistent Cursor session hooks and relies on an unpinned remote registry install, making its footprint broader than necessary for a simple topbar integration. No clear credential theft or exfiltration is present, but install-trust and persistence concerns make this higher than benign.

Confidence: 83%Severity: 56%
Audit Metadata
Analyzed At
Apr 27, 2026, 03:21 AM
Package URL
pkg:socket/skills-sh/cognitedata%2Fdune-skills%2Fuse-topbar%2F@7f61669885eb6be7f73abab92771cfc23197d3cb