wxt-skills

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/svelte/package.json

The postinstall script will execute the 'wxt' CLI during install. There is no direct evidence in this package.json of malicious content (no external URLs, no non-registry dependency references), but running a third-party CLI at install time is a potential supply-chain risk because that CLI (or its transitive dependencies) could execute arbitrary code, exfiltrate data, or modify the system. Recommend auditing the 'wxt' package (check its package.json scripts, published files, maintainers, recent changes, and any postinstall behavior), pining to a vetted version, or removing/avoiding automatic postinstall execution if you cannot fully trust the upstream package.

Confidence: 80%Severity: 60%
Audit Metadata
Analyzed At
Feb 20, 2026, 01:27 AM
Package URL
pkg:socket/skills-sh/morning-start%2Fcoze-skills%2Fwxt-skills%2F@94f940b7debe4d50d3e39fe29f458f94411b6aa4