dev-test-electron

Warn

Audited by Socket on Mar 27, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/cdp-commands.json

Best matching assessment: this fragment is a CDP/Electron automation command catalog, but it includes “misuse-ready” capability examples—arbitrary Runtime.evaluate execution, Node/Electron require escalation, local file read (/app/config.json), IPC user-data retrieval, and HTTP response-body extraction. While the artifact itself may be intended for testing/documentation, its included primitives substantially elevate supply-chain misuse risk. Additional context is needed to confirm actual runtime execution and whether network/IPC paths are reachable by an attacker.

Confidence: 60%Severity: 62%
Audit Metadata
Analyzed At
Mar 27, 2026, 12:47 PM
Package URL
pkg:socket/skills-sh/edwinhu%2Fworkflows%2Fdev-test-electron%2F@49fe6f356edd1b85fdb65230a2b7d992648f4372