shiny-bslib-theming

Warn

Audited by Socket on Feb 20, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Backtick command substitution detected All findings: [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] This document is legitimate documentation for the bslib theming system for Shiny apps. It describes expected behavior (local file discovery, Sass rule inclusion, Google Fonts downloads, and developer theming tools). There is no evidence of malicious code or hidden exfiltration. The security concerns are operational: auto-discovery of _brand.yml can let untrusted local files affect theme generation, and font downloads introduce a network dependency. Developers should disable auto-discovery or host fonts locally in high-threat environments and remove development helpers (bs_themer/run_with_themer) from production deployments. LLM verification: Benign: The skill fragment aligns with its stated purpose of enabling advanced theming for Shiny apps via bslib, with normal dependencies on font resources and branding configuration. The only notable observations are documentation formatting artifacts (backticks) and routine network I/O for fonts, which are expected in this domain. No malicious activity or data exfiltration detected within the provided fragment.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Feb 20, 2026, 08:52 PM
Package URL
pkg:socket/skills-sh/posit-dev%2Fskills%2Fshiny-bslib-theming%2F@f4f2c51caccba8b7b425fd5ec2d1a2c0867b23e9