tauri-app-dev

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [CRITICAL] command_injection: Instruction to copy/paste content into terminal detected (CI012) [AITech 9.1.4] [CRITICAL] command_injection: Instruction directing agent to run/execute external content (CI011) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] [HIGH] command_injection: Backtick command substitution detected (CI003) [AITech 9.1.4] BENIGN. The skill fragment is coherent with its stated purpose (expert TAURI 2.0 app development guidance). It demonstrates typical, legitimate capabilities (IPC, file dialogs, FS access, state management, plugins, security capabilities) and uses standard sources of truth (official TAURI APIs, Cargo/npm tooling). Data flows and permissions are aligned with a desktop app scenario and do not indicate credential harvesting, covert data exfiltration, or other malicious behaviors. The footprint is proportionate to the described guidance skill; no suspicious install sources or hidden data flows are evident. LLM verification: The skill fragment is benign and coherent with its stated purpose as a development and security guidance document for Tauri app creation. There are no actionable credentials, no hidden network calls, and no data exfiltration behavior embedded in the provided content. The few scanner findings appear to be documentation phrasing (e.g., template strings, environment placeholders) rather than executable code or dangerous instructions. Overall, the piece is appropriate for its intended use as an inst

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 17, 2026, 07:40 AM
Package URL
pkg:socket/skills-sh/xiaolai%2Fvmark%2Ftauri-app-dev%2F@05644ade910a1e1a42e69fa92f622d0c880f9ae0