vue-creater

Fail

Audited by Socket on Mar 9, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

Overall, the skill footprint is coherent with its stated purpose of scaffolding Vue-based frontend projects with optional design tokens. The main risk vectors involve remote data retrieval for DSL tokens and the reliance on local scripts to execute potentially sensitive project setup, which warrants attention to source trust and input validation. No direct credential exposure or unauthorized data exfiltration is evident from the provided documentation. Security risk remains moderate (due to remote data sources and session-state handling) and can be mitigated with explicit trust checks, input validation, and pinning of token sources.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:33 AM
Package URL
pkg:socket/skills-sh/helloggx%2Fskill%2Fvue-creater%2F@f27bf8bffa6380ad0cb15c8e843f7336f4961c74