hyperframes-overview-edit

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Security
SecurityMEDIUM
serve-live.py

This Python module implements an unauthenticated HTTP endpoint that accepts attacker-controlled patch instructions and persistently overwrites index.html and overview.html within a startup-configured directory. The patch’s NEW content is injected verbatim into HTML without sanitization, creating a strong stored content injection/sabotage risk (e.g., persistent XSS/defacement if rendered by users). While the fragment shows no classic malware behaviors like command execution or external exfiltration, the write-capable remote control over build/served artifacts makes it security-relevant and potentially dangerous in a supply-chain context.

Confidence: 68%Severity: 72%
Audit Metadata
Analyzed At
Aug 21, 2026, 06:42 PM
Package URL
pkg:socket/skills-sh/canine89%2Fagent-slide-maker-easy%2Fhyperframes-overview-edit%2F@4762ec8e06b3205dac5183730f8ac89764ad0858dce7aa9c6efe0c6369d40058
Security Audit — socket — hyperframes-overview-edit