baoyu-format-markdown

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/autocorrect.ts

This module’s intent is benign (run a formatting/autocorrection tool), but it constructs and executes a shell command using execSync with direct interpolation of a caller-controlled filePath, creating a command-injection risk if filePath is attacker-influenced. It also relies on npx to execute an external tool/package at runtime, which increases execution/supply-chain exposure in the broader environment. No direct malicious payload behavior (e.g., network exfiltration, credential theft, persistence, obfuscation) is evident in this snippet alone.

Confidence: 74%Severity: 66%
Audit Metadata
Analyzed At
Aug 14, 2026, 04:00 PM
Package URL
pkg:socket/skills-sh/atxinsky%2Fskills%2Fbaoyu-format-markdown%2F@7a5343fd6ffa0eb628288ad89b050d20e9c15c426366e66c63a386ca30264f44
Security Audit — socket — baoyu-format-markdown