workbuddy-theme-manager

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/workbuddy-theme.mjs

This module is a powerful local injection tool that connects to a desktop app’s Chromium DevTools endpoint and injects/evaluates JavaScript derived from theme packages using Runtime.evaluate and Page.addScriptToEvaluateOnNewDocument. There is no direct evidence in the snippet of malware-like network exfiltration or credential theft, but the design can enable arbitrary code execution in the target renderer if an attacker controls the theme input or tampers with local state. Treat untrusted themes/state as unsafe and restrict where packages come from.

Confidence: 68%Severity: 55%
Audit Metadata
Analyzed At
Jul 21, 2026, 09:14 AM
Package URL
pkg:socket/skills-sh/codexthemes%2Fskills%2Fworkbuddy-theme-manager%2F@f0b9a39bbae8bbb01fdb24955f7a9d4c98934d88003efa32aece246b5a097426
Security Audit — socket — workbuddy-theme-manager