ui-designer

Fail

Audited by Socket on Feb 23, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

No direct malicious code or backdoor is present in the provided skill description. The main security concerns are operational and supply-chain: (1) the unspecified general-purpose subagent that receives full images/text could leak sensitive data if it executes remotely — confirm its runtime and privacy guarantees before use; (2) commands that run npx/npm install are necessary for scaffolding but are supply-chain risk if executed automatically — require explicit user consent and pin package sources/versions. Recommend adding disclosure about where the Task tool runs, interactive confirmations before network installs or uploads, and explicit guidance on handling proprietary images/PII.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 23, 2026, 05:30 AM
Package URL
pkg:socket/skills-sh/nguyendinhquocx%2Fcode-ai%2Fui-designer%2F@180e8dc709d79fc86e2517735ed3c5f1713fb6b9