stylekit-style-prompts

Warn

Audited by Socket on May 30, 2026

1 alert found:

Anomaly
AnomalyLOW
bin/stylekit-skill.js

No direct signs of overt malware (no exfiltration/networking/credential theft/obfuscation) are evident in this module. The primary security risk is operational/safety: recursive forced deletion and recursive copying are performed to a destination derived from a user-controlled --target (path.resolve(expandHome(...)) without allowlisting), which could lead to accidental or abusive destruction/overwrite of arbitrary directories. Additionally, doctor() executes python3 and imports a module from the bundled payload’s scripts directory, so a tampered payload could execute arbitrary Python code during validation.

Confidence: 62%Severity: 64%
Audit Metadata
Analyzed At
May 30, 2026, 12:21 PM
Package URL
pkg:socket/skills-sh/AnxForever%2Fstylekit-skill%2Fstylekit-style-prompts%2F@caebe3c485bcdfbae57ee13e4fb8ab55f46cf9b7
Security Audit — socket — stylekit-style-prompts