baoyu-format-markdown

Warn

Audited by Socket on Jul 26, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/autocorrect.ts

This module’s intent is benign (run a formatting/autocorrection tool), but it constructs and executes a shell command using execSync with direct interpolation of a caller-controlled filePath, creating a command-injection risk if filePath is attacker-influenced. It also relies on npx to execute an external tool/package at runtime, which increases execution/supply-chain exposure in the broader environment. No direct malicious payload behavior (e.g., network exfiltration, credential theft, persistence, obfuscation) is evident in this snippet alone.

Confidence: 74%Severity: 66%
Audit Metadata
Analyzed At
Jul 26, 2026, 07:46 PM
Package URL
pkg:socket/skills-sh/anbeime%2Fskill%2Fbaoyu-format-markdown%2F@abb75469fd3bffce9fc7ec2342ef456ea978f41a8396d9345be7150449881949
Security Audit — socket — baoyu-format-markdown