autobrowse
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalycodegen/runners/lib/tsx-runner.mjs
LOWAnomalyLOW
codegen/runners/lib/tsx-runner.mjs
This is an automated verification runner that installs dependencies, launches a TypeScript script, captures its output, and records a screenshot directory. It contains powerful intentional process-execution behavior, but the visible code does not show credential theft, network exfiltration, persistence, destructive file operations, cryptomining, or obfuscated payloads. The main security concern is that untrusted `--out-dir` or `--script` values can cause arbitrary npm lifecycle scripts or TypeScript code to execute, with inherited environment access.
Confidence: 98%Severity: 62%
Audit Metadata