data-fair-app

Warn

Audited by Socket on Oct 3, 2026

1 alert found:

Anomaly
AnomalyLOW
snippets/create-config-light.ts

No clear indicators of overt malware (no exec/eval, no external network requests, no credentials or persistence). However, the module has a high-impact security weakness: it accepts untrusted postMessage events without validating event.origin/event.source and uses an attacker-controlled dot-path writer (setByPath) to mutate nested configuration. This combination can enable configuration tampering and potentially prototype/structure pollution, which may lead to broader downstream security issues depending on how other parts of the app consume the provided config. Hardening should focus on strict postMessage origin/source verification, payload schema validation/whitelisting, and blocking dangerous path segments in setByPath.

Confidence: 68%Severity: 62%
Audit Metadata
Analyzed At
Oct 3, 2026, 06:41 PM
Package URL
pkg:socket/skills-sh/data-fair%2Flib%2Fdata-fair-app%2F@9c2390be421585881c445535eb38751a1cafeced8f0cbd5b8174a196d4e4bdaa
Security Audit — socket — data-fair-app