convert-tanstack-app-to-web-component

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the described skill/pattern is coherently aligned with its stated purpose of delivering a framework-agnostic Web Component wrapper around a TanStack app. There are no credential exposures, no remote data exfiltration patterns, and no suspicious download-execute behavior described. The only notable considerations are standard supply-chain risk practices: rely on official registries, pin versions where possible, and ensure the host environment trusts the dist artifact. Given the combination of inline CSS in shadow DOM, custom element creation, and a separate WC build config, the footprint is proportionate to the stated goal of a WC add-on for a TanStack app.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 04:54 PM
Package URL
pkg:socket/skills-sh/Visio-ai%2Fteste-skills%2Fconvert-tanstack-app-to-web-component%2F@e8ffd863a016a2d0f091e6bfb69333d626c32666