frontend-audit

Warn

Audited by Socket on Jun 20, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/bootstrap-regions.mjs

No direct evidence of intentional malware (e.g., exfiltration/backdoor/credential theft) is present in the shown JavaScript fragment. However, it performs runtime provisioning of a large ML Python stack via pip (including potentially unpinned or variable dependencies) and then executes a local Python helper whose contents are not included here; stdout from that helper is trusted and becomes the basis for filesystem writes. This creates meaningful supply-chain and execution integrity risk, with an additional artifact placement/overwrite risk derived from --image and enabled overwrite via --force.

Confidence: 60%Severity: 65%
Audit Metadata
Analyzed At
Jun 20, 2026, 02:57 PM
Package URL
pkg:socket/skills-sh/colbymchenry%2Ffrontend-audit-skill%2Ffrontend-audit%2F@2f35be45a1346d240592a0af81ce16d8fce95969
Security Audit — socket — frontend-audit