fal-redesign

Warn

Audited by Socket on May 10, 2026

1 alert found:

Anomaly
AnomalyLOW
runtime/src/review.mjs

This module is primarily an LLM-assisted website rewrite/screenshot pipeline with meaningful security exposure: it transmits the full local HTML and rendered screenshot to external AI services, and it writes unsanitized LLM-generated HTML back to index.html (potentially introducing executable client-side content). While there is no direct evidence of backdoor/credential-stealing logic in this fragment, the trust boundary is large and the content-integrity risk is substantial if the resulting HTML is ever served or if the brief/HTML can be adversarial.

Confidence: 67%Severity: 58%
Audit Metadata
Analyzed At
May 10, 2026, 02:57 PM
Package URL
pkg:socket/skills-sh/fal-ai-community%2Fskills%2Ffal-redesign%2F@54017eaee06692df057a8431484a2203a6e5abcb