visual-planner

Warn

Audited by Socket on Sep 22, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
playground/src/app/api/signal/route.ts

The code appears to implement an intentional file-backed webhook or update mechanism rather than malware. It has a moderate deployment-dependent security risk because unauthenticated callers may be able to overwrite the configured server-side file, and the module does not impose input limits, validate the JSON schema, or validate the configured path. No clear malicious behavior is present in the supplied fragment.

Confidence: 98%Severity: 58%
AnomalyLOW
playground/src/app/api/workflow/route.ts

No indicators of intentional malware or supply-chain sabotage are present. The code implements a file-backed JSON API, but it presents a potentially significant access-control risk if the route is publicly accessible: GET can disclose the configured file and POST can overwrite it. TLDR_FILE should be constrained to an intended data file and the endpoints should enforce authentication, authorization, and appropriate request protections.

Confidence: 98%Severity: 68%
Audit Metadata
Analyzed At
Sep 22, 2026, 03:38 PM
Package URL
pkg:socket/skills-sh/b-open-io%2Fgemskills%2Fvisual-planner%2F@dfb27cdc90d1de1633c672bb06551700f08536ff731e1082938ac473e1171cf9