tavern-ui

Warn

Audited by Socket on Aug 25, 2026

2 alerts found:

AnomalySecurity
AnomalyLOW
SKILL.md

总体上这是一个与其声明用途基本一致的前端开发 skill,不像凭据窃取或明显恶意内容。主要风险来自供应链:依赖个人 GitHub 模板仓库、执行其包脚本、以及通过第三方镜像/远程 URL 动态加载前端页面,因此应归为可疑但非恶意。

Confidence: 82%Severity: 56%
SecurityMEDIUM
references/environments/tavern-helper-runtime.md

No direct evidence of explicit malware is present in the provided text because it is architectural/runtime documentation rather than auditable executable code. However, the described design significantly increases risk: iframes are not sandboxed, message-floor iframes can directly access the parent without the described Proxy-based cleanup wrapper, and user code runs after synchronous CDN script pre-injection. This combination materially raises the blast radius of any dependency compromise or injected script, and should be treated as a high-priority security review area (with emphasis on dependency integrity, CDN trust/SRI/pinning, and verifying the actual implementations of predefine.js/cleanup protector and any network behavior).

Confidence: 42%Severity: 74%
Audit Metadata
Analyzed At
Aug 25, 2026, 12:24 AM
Package URL
pkg:socket/skills-sh/ai4rpg%2Ftavern-cards%2Ftavern-ui%2F@16d244c3be50a1fcf9582c0e3c652bfdc8ad5cbb5b512971d671a4632ea02e56
Security Audit — socket — tavern-ui