codify-design-to-code

Warn

Audited by Socket on Apr 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/download-screenshot.cjs

No strong indicators of intentional malware/backdoor behavior in this module (no dynamic code execution or external exfiltration). However, the script trusts a local service on a fixed port and writes attacker-controlled content to a user-specified path with minimal path validation, creating meaningful security risk: arbitrary file overwrite within process permissions and potential privacy-impacting screenshot retrieval if misused or if an attacker can supply/impersonate the local server. Use in trusted environments only and restrict/validate --output and the expected local service behavior.

Confidence: 66%Severity: 62%
Audit Metadata
Analyzed At
Apr 21, 2026, 03:20 AM
Package URL
pkg:socket/skills-sh/chenaey%2Fcodify-dev-skill%2Fcodify-design-to-code%2F@9c897fd07655ab0fc9dba34dbd1a48f454c4cd4f