co-star-ui
Fail
Audited by Socket on Mar 9, 2026
1 alert found:
Obfuscated FileObfuscated FileSKILL.md
HIGHObfuscated FileHIGH
SKILL.md
The CO-STAR UI skill is coherently scoped to its stated purpose: guiding UI work and custom CO-STAR prompt creation with discovery-first workflows. It does not appear to require or transmit credentials, perform remote actions, or download/install unknown binaries. The security footprint is low and proportional to its design/prompting focus. No evident data exfiltration or supply-chain risks are present in the described content. Overall, the skill is benign with respect to security posture, assuming usage remains within documented discovery, planning, and UI/prompt-generation activities.
Confidence: 98%
Audit Metadata