front-review

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/js/cart-service.js

The code does not show evidence of malware or intentional supply-chain sabotage. It contains a potential XSS vulnerability because server-provided item.name values are inserted into innerHTML without escaping. It also lacks validation and encoding for userId and promotion data. Use DOM text APIs or explicit HTML escaping, validate API schemas and discount bounds, and encode the URL path parameter.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:23 PM
Package URL
pkg:socket/skills-sh/effeilo%2Fclaude-code-frontend-skills%2Ffront-review%2F@5a35b59d11c167eb41acac5c334564b15042a33e7969b55597374e71850e4267
Security Audit — socket — front-review