dev-test-electron
Warn
Audited by Socket on Mar 27, 2026
1 alert found:
AnomalyAnomalyexamples/cdp-commands.json
LOWAnomalyLOW
examples/cdp-commands.json
Best matching assessment: this fragment is a CDP/Electron automation command catalog, but it includes “misuse-ready” capability examples—arbitrary Runtime.evaluate execution, Node/Electron require escalation, local file read (/app/config.json), IPC user-data retrieval, and HTTP response-body extraction. While the artifact itself may be intended for testing/documentation, its included primitives substantially elevate supply-chain misuse risk. Additional context is needed to confirm actual runtime execution and whether network/IPC paths are reachable by an attacker.
Confidence: 60%Severity: 62%
Audit Metadata