convert-tanstack-app-to-web-component
Warn
Audited by Socket on Feb 26, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the described skill/pattern is coherently aligned with its stated purpose of delivering a framework-agnostic Web Component wrapper around a TanStack app. There are no credential exposures, no remote data exfiltration patterns, and no suspicious download-execute behavior described. The only notable considerations are standard supply-chain risk practices: rely on official registries, pin versions where possible, and ensure the host environment trusts the dist artifact. Given the combination of inline CSS in shadow DOM, custom element creation, and a separate WC build config, the footprint is proportionate to the stated goal of a WC add-on for a TanStack app.
Confidence: 75%Severity: 75%
Audit Metadata