codex-theme-switcher

Warn

Audited by Socket on Jul 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/switch-theme.ts

No direct evidence of classic malware (exfiltration, credential theft, cryptomining, or backdoor persistence) is present in this fragment. However, the library/tool performs high-impact, dynamic code injection into a local renderer via CDP (Page.addScriptToEvaluateOnNewDocument and Runtime.evaluate) using JS source derived from theme/manifest data. If a supply-chain attacker can influence theme contents or identifiers/state, this becomes effectively arbitrary code execution in the target app context. This is a security hotspot that should be reviewed for strict input validation and sandboxing (themeDir resolution, manifest.id/backgroundScope constraints, and any controls on theme provenance).

Confidence: 68%Severity: 62%
Audit Metadata
Analyzed At
Jul 19, 2026, 09:27 AM
Package URL
pkg:socket/skills-sh/codexthemes%2Fskills%2Fcodex-theme-switcher%2F@cc0d84ad26f2737b488f38913c77a80ba8b34318a9d43ea31b5aae0c1fb83dcf
Security Audit — socket — codex-theme-switcher