create-html-report

Warn

Audited by Socket on Sep 23, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/report.js

The visible code appears to be a legitimate client-side reporting and visualization framework, not malware. The main security risk is unsafe dynamic code execution in initCalc(), where HTML attributes are compiled with new Function(). This is acceptable only when the report HTML and its data attributes are fully trusted; it should be replaced with a constrained expression parser for untrusted content. Mermaid loose security settings, dynamic CDN dependencies, and some innerHTML-based SVG generation warrant review for untrusted inputs. No evidence of data theft, persistence, system compromise, or sabotage is present.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 23, 2026, 08:27 AM
Package URL
pkg:socket/skills-sh/alfonsograziano%2Fskills%2Fcreate-html-report%2F@5e8b7fa65d0127828c92e633876bce976f8c843776b1f7b2d620b428b44044b9
Security Audit — socket — create-html-report