maui-aspire

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the fragment is coherently aligned with its stated purpose of guiding MAUI integration with Aspire services. The most notable risk stems from documented download/install steps that fetch external scripts/skills; if these commands are executed automatically in CI/CD or via automated agent workflows, they could introduce supply-chain risk. Other patterns (token-based auth flow, environment-based URLs, and platform-specific networking) are appropriate for the target use case but should be strictly version-controlled and validated. Treat the provisioning/download instructions as the primary supply-chain risk signal and ensure they are executed with strict verification (code/signature checks, pinning, and reproducible builds).

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 12:07 AM
Package URL
pkg:socket/skills-sh/davidortinau%2Fmaui-skills%2Fmaui-aspire%2F@b345a84dbbc8f3c1bef11e50183a232f1347cd83