magicpath

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's capabilities mostly match its stated UI-component workflow, but it requires trusting an external CLI with broad wildcard access and uses mutable npm execution paths. The stronger concern is data-flow integrity: the agent ingests remote component/theme content and then writes code locally, creating meaningful indirect prompt-injection and supply-chain risk. No clear credential theft or overtly malicious exfiltration is shown.

Confidence: 82%Severity: 62%
Audit Metadata
Analyzed At
Mar 27, 2026, 05:25 PM
Package URL
pkg:socket/skills-sh/magicpathai%2Fagent-skills%2Fmagicpath%2F@de0990e8fd5e870086bba6304a5476b6fafb370f