editframe-vite-plugin

Warn

Audited by Socket on May 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/file-api.md

The described local development API surface is conventional for development tooling and mirrors production endpoints. Primary security concerns center on access controls for local filesystem access, potential path traversal, and management of in-memory legacy mappings. With proper isolation (dev-only network, authentication, input sanitization, and memory management), the risk is manageable. If deployed in a broader or production-like environment without safeguards, it could enable unauthorized access to local assets and cache data exposure.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
May 12, 2026, 01:26 AM
Package URL
pkg:socket/skills-sh/editframe%2Fskills%2Feditframe-vite-plugin%2F@c7a90047c5ca7dcdec14a3669b17ef8ae25e785a