dxf

Warn

Audited by Socket on Aug 21, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/packages/cadgen/src/cadgen/_internal/generation_runner.py

This module is a CAD generation orchestrator that dynamically loads and executes Python generator plugins from a filesystem path (exec_module + generator() call). It validates the *returned payload structure* but cannot restrict what the plugin code does during import/execution. No explicit overt malware (network exfiltration, credential theft, reverse shell) is visible in this fragment; the primary risk is the inherent arbitrary-code-execution trust boundary, which would enable build-time sabotage or data theft if an attacker can influence the generator module path/content. Truncation at the end of the file slightly limits review of cleanup/lock semantics.

Confidence: 62%Severity: 66%
AnomalyLOW
scripts/packages/cadgen/src/cadgen/_internal/node_resolve_register.mjs

This module is a minimal bootstrap that registers a local Node.js resolution hook (node_resolve_hooks.mjs) using the privileged node:module register mechanism. While the snippet itself shows no explicit malicious actions, the hook-based approach is high-impact and can be used to alter dependency resolution/execution, making it a supply-chain/runtime tampering red flag pending review and verification of node_resolve_hooks.mjs (content, integrity, and whether it only performs intended legitimate resolution behavior).

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Aug 21, 2026, 04:25 PM
Package URL
pkg:socket/skills-sh/earthtojake%2Ftext-to-cad%2Fdxf%2F@c7fb72e3d07b89b4f9fe7471c24ad05bb8e58c514814b434ab1cc5be79576536
Security Audit — socket — dxf