craft-ui

Warn

Audited by Socket on Aug 31, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/render-server.ts

No strong indicators of intentional malware (no process execution, no outbound network behavior, no credential theft, no obfuscation, and no backdoor-like persistence) are present in this module. The primary risks are local abuse and trust-boundary issues: (1) unauthenticated event logging to a persistent .events file from arbitrary JSON (integrity/data poisoning and disk growth risk), and (2) potential filename-based XSS/markup injection in the gallery UI because filenames from the session directory are interpolated into HTML and attribute contexts without robust escaping. If sessionDir is fully trusted and the server is only reachable to the intended local user, risk is reduced, but security review is still warranted for the HTML/template encoding and event ingestion hardening.

Confidence: 63%Severity: 55%
Audit Metadata
Analyzed At
Aug 31, 2026, 07:25 PM
Package URL
pkg:socket/skills-sh/adeonir%2Fagent-skills%2Fcraft-ui%2F@34816ad0035dd73eb62063273242333b534897a9d774893df3ba095804e2b899
Security Audit — socket — craft-ui