vueuse-functions

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected All findings: [CRITICAL] command_injection: Natural language instruction to download and install from URL detected (CI009) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] [HIGH] supply_chain: Download or install from free hosting/deployment platform detected (SC007) [AITech 9.1.4] The skill fragment is benign and coherent with its stated purpose as a decision-and-implementation guide for VueUse composables in Vue.js/Nuxt projects. There are no code executions, no credential requirements, and no data flows to assess beyond static documentation. Overall security posture is appropriate for its intended function. LLM verification: The fragment is largely aligned with its stated purpose of guiding VueUse usage. The primary concern is the presence of references to external download/installation resources within the static document, which could enable unsafe runtime behavior if exploited. Absent explicit, sandboxed, and user-consented procedures for external fetches, treat the external links pattern as a supply-chain risk. Recommend restricting the fragment to self-contained guidance and removing or clearly gating any extern

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:48 PM
Package URL
pkg:socket/skills-sh/kirklin%2Fskills%2Fvueuse-functions%2F@814292ecd8c7a8bd7edc3105d3135aa7e60cf9a1