react-performance

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected The skill fragment is internally consistent and proportionate to its stated purpose of guiding a React performance optimization expert. It does not introduce suspicious data flows, credential access beyond normal tooling, or external communications that would indicate malicious intent. Overall, the piece is BENIGN with moderate confidence given the absence of executable code or secret-handling behaviors. LLM verification: This SKILL.md is a benign, instructional React performance guidance document. Its capabilities (filesystem checks, package probes, profiling guidance, and suggested npm installs) are consistent with the stated purpose. Static scanner hits are false positives caused by example commands and config-file references. The only operational caution: the document suggests unpinned npm installs — users should pin versions and vet packages before installing. No evidence of obfuscated code or malicious beha

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:18 AM
Package URL
pkg:socket/skills-sh/duck4nh%2Fantigravity-kit%2Freact-performance%2F@ee144b8b0c7a5bdb2e775ca1f36a1dc1fc329657