component-gen

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose is coherent for a component-generation skill, but the trust chain is incomplete: it asks the agent to run an external `npx` package and provide `OPENAI_API_KEY` without enough evidence here that the package is official, published by the claimed org, or safely documented. If `ai-component` is not verifiably the same publisher's official npm package, this becomes credential forwarding to third-party code and materially raises risk.

Confidence: 81%Severity: 72%
Audit Metadata
Analyzed At
Mar 23, 2026, 05:40 PM
Package URL
pkg:socket/skills-sh/sundial-org%2Fawesome-openclaw-skills%2Fcomponent-gen%2F@46e66d3983be0cd1da0d4c8921326cc222304775