react-performance

Warn

Audited by Socket on Feb 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

This SKILL.md and included code examples are coherent with their stated purpose (React performance education). There are no signs of credential harvesting, exfiltration, dynamic code-evaluation tricks, obfuscation, or malicious network endpoints. Risk is limited to normal supply-chain trust of third-party packages you choose to install (e.g., xlsx, react, web-vitals). Recommend standard package vetting (pinning versions, auditing dependencies) but the skill content itself appears benign.

Confidence: 90%Severity: 12%
Audit Metadata
Analyzed At
Feb 15, 2026, 09:34 PM
Package URL
pkg:socket/skills-sh/pluginagentmarketplace%2Fcustom-plugin-react%2Freact-performance%2F@4951821303d89c9793669e9cfcc29ff7e10c2270