veld-feedback
Warn
Audited by Socket on Mar 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The skill’s stated purpose is coherent for frontend review, but its trust boundary is weak because it depends on an unverifiable `veld` CLI with no official install provenance or documented backend endpoints. The external feedback loop is plausible, yet the opaque binary and external-content-driven code editing make this a high security-risk skill without enough evidence to call it malicious.
Confidence: 83%Severity: 82%
Audit Metadata