ui-ux-pro-max

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] The fragment is a benign, well-structured design guidance artifact describing a UI/UX design intelligence workflow. It provides a clear path to generate design systems via local tooling and domain searches, with emphasis on accessibility and UX best practices. Recommended for use in controlled environments with validated local scripts and proper versioning of design assets. LLM verification: The README itself is benign documentation for a UI/UX skill, but it directs users to execute a bundled Python script whose implementation and network endpoints are not provided. That creates a moderate supply-chain risk: running the script could lead to arbitrary code execution, local data access, or network exfiltration. Prior to use, inspect the script, verify provenance (repo/checksum), and run it with limited privileges or in a sandbox. If the script is audited and only calls known, safe pub

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 10:55 AM
Package URL
pkg:socket/skills-sh/poletron%2Fcustom-rules%2Fui-ux-pro-max%2F@cfe40239ca6b35de493e38b9b7e659403f23c40a