frontend-ui

Fail

Audited by Socket on Apr 12, 2026

2 alerts found:

SecurityObfuscated File
SecurityMEDIUM
SKILL.md

SUSPICIOUS. Most capabilities fit a UI-generation skill, but the built-in workflow to install a separate third-party skill (`icon-craft`) creates a disproportionate transitive supply-chain risk. External web research plus write/exec tools adds moderate prompt-injection risk, though there is no clear credential harvesting or exfiltration behavior.

Confidence: 89%Severity: 74%
Obfuscated FileHIGH
knowledge/workflow/phase4-generation.md

Overall, the provided fragment is a design- and process-oriented specification with no executable code present to evaluate for malware or data leakage. The main actionable item is to ensure the DESIGN CONTRACT block is present and satisfies the Phase 4.5 audit criteria, and to verify that no forbidden patterns are introduced by the actual generation output. The security risk from this fragment alone is low; the risk would derive from downstream implementation and automation pipelines if misused or misconfigured.

Confidence: 98%
Audit Metadata
Analyzed At
Apr 12, 2026, 06:38 AM
Package URL
pkg:socket/skills-sh/instantX-research%2Fskills%2Ffrontend-ui%2F@6ecf7cbfa70507bde6e9b70e4d6b47834cc9c6c7