deploy

Warn

Audited by Socket on Aug 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/style-fingerprint.mjs

The code is a readable browser-based webpage style-analysis utility, not apparent malware. It performs no explicit data theft or persistence, but passing an unvalidated command-line URL to Playwright creates a meaningful arbitrary-navigation/SSRF and untrusted-page execution risk. Restrict allowed schemes and hosts, isolate the browser, disable or constrain access to local and private networks, and avoid sensitive browser credentials.

Confidence: 98%Severity: 55%
Audit Metadata
Analyzed At
Aug 26, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/adobe%2Fskills%2Fdeploy%2F@031cf4686ef021b5c418e1301d7bc621ed4c99a17c6e67def9b7e847fe18d061
Security Audit — socket — deploy