web-asset-generator

Warn

Audited by Socket on Mar 4, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Benign: the code fragment outlines a legitimate, user-driven asset-generation workflow with clearly defined scripts, dependencies, and test/validation steps. There are no direct malicious data flows, credential handling, or covert exfiltration patterns evident in the fragment. The primary risks are normal supply-chain concerns around dependency installation from PyPI and integration into user projects; ensure proper sanitization of uploaded assets and integrity checks for scripts and dependencies in a real implementation.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 4, 2026, 04:15 PM
Package URL
pkg:socket/skills-sh/leduxro-prog%2Ferp-dashboard%2Fweb-asset-generator%2F@b17199e3524fb2cdda42a10557ac5e2c277705d5