frontend

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] hardcoded_secrets: Generic secret pattern detected (HS005) [AITech 8.2] [HIGH] hardcoded_secrets: Generic secret pattern detected (HS005) [AITech 8.2] The Fragment is a coherent, purpose-aligned collection of guides and samples for MultiversX frontend development. Its footprint matches the stated goals: enabling wallet integration, transaction construction and signing, contract interactions, and UI patterns. There are no evident malicious capabilities or credential harvesting mechanisms within the code samples themselves. A legitimate developer could use this material to build secure dApps; attention should be paid to replacing placeholders with real values and strictly avoiding testing-only credentials in production.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 12:55 PM
Package URL
pkg:socket/skills-sh/michavie%2Fmx-ai-skills%2Ffrontend%2F@012357091b23b81446b48bd3adf4165a63d93890