archify

Fail

Audited by Socket on Sep 28, 2026

3 alerts found:

Anomalyx2Malware
AnomalyLOW
bin/visual-check.mjs

No direct signs of intentionally malicious supply-chain behavior (e.g., exfiltration, credential theft, hidden backdoors) are present in this code fragment. However, it is a high-impact automation harness: it spawns and CDP-controls a real headless Chrome instance, navigates to a caller-provided local HTML artifact (file://), and executes page-context JavaScript via Runtime.evaluate against that artifact. The optional --no-sandbox behavior (root or ARCHIFY_CHROME_NO_SANDBOX=1) meaningfully increases risk if the artifact is attacker-controlled. Treat as low-to-medium malware likelihood, but elevated operational security risk when processing untrusted HTML.

Confidence: 64%Severity: 56%
AnomalyLOW
bin/preview.mjs

No clear indicators of overt malware (no keylogging, no system data exfiltration to external domains, no reverse shell). However, the module can execute a child CLI using an executable/script path that may be caller-controlled via options.deliveryCli, and it serves HTML produced by that child directly to the browser. The combination of untrusted-influenced HTML delivery and a permissive CSP for the main page (script-src 'unsafe-inline') makes this a noteworthy security risk for XSS in the local preview context. Overall: likely benign for its intended purpose, but with important execution-content risks requiring strict control of options.deliveryCli and input content.

Confidence: 72%Severity: 58%
MalwareHIGH
test/fixtures/fail-migration-cleanup.mjs

This dependency is strongly suspicious: it monkey-patches a core filesystem deletion API to cause a targeted, one-time fabricated EPERM error for directory basenames starting with '.archify-migration-'. Although the real deletion is invoked before throwing, the thrown error can mislead migration/cleanup logic and disrupt deployments or leave inconsistent state. No evidence of data exfiltration or remote control exists in this module, but the sabotage behavior poses a high security risk in a supply-chain context.

Confidence: 86%Severity: 90%
Audit Metadata
Analyzed At
Sep 28, 2026, 03:50 PM
Package URL
pkg:socket/skills-sh/aiskillstore%2Fmarketplace%2Farchify%2F@8bb4dff83c226ea5f62e2e0e7d7c586098e930d8f6b8489c938ecb020e350446