visual-planner
Audited by Socket on Sep 22, 2026
2 alerts found:
Anomalyx2The code appears to implement an intentional file-backed webhook or update mechanism rather than malware. It has a moderate deployment-dependent security risk because unauthenticated callers may be able to overwrite the configured server-side file, and the module does not impose input limits, validate the JSON schema, or validate the configured path. No clear malicious behavior is present in the supplied fragment.
No indicators of intentional malware or supply-chain sabotage are present. The code implements a file-backed JSON API, but it presents a potentially significant access-control risk if the route is publicly accessible: GET can disclose the configured file and POST can overwrite it. TLDR_FILE should be constrained to an intended data file and the endpoints should enforce authentication, authorization, and appropriate request protections.