sveltia-cms

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

No direct malicious code or obfuscation is present in this SKILL.md. The documented capabilities align with the stated purpose and requested credentials are proportional to a GitHub-backed CMS. The main security concern is supply-chain and operational: the OAuth flow routes through a Cloudflare Worker proxy and the CMS JavaScript is loaded from unpkg — both are legitimate but require the operator to trust and verify the external repos and deployed endpoints. If an attacker controls the worker endpoint or the CDN-hosted bundle, they could harvest OAuth codes/tokens or perform unauthorized repository access. Recommend verifying the sveltia-cms-auth repository source, pinning bundle versions, hosting JS locally if possible, and auditing deployed worker code before providing client secrets.

Confidence: 39%Severity: 45%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:55 PM
Package URL
pkg:socket/skills-sh/jezweb%2Fclaude-skills%2Fsveltia-cms%2F@df61e6c7a3d45a1f0574b3c5d6ff2380c82cbe67