experience-lwc-runtime-observe

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/component-preview-and-dom.md

No direct evidence of overt malware (e.g., exfiltration to external domains, reverse shells, or persistence) is present in this fragment. The primary security concern is command execution risk caused by `eval` of stdout produced by an external helper script; this is a classic supply-chain sabotage vector if helper integrity/outputs are not strictly controlled. A secondary concern is potential exposure of sensitive rendered content because the tool extracts shadow DOM innerHTML and emits it to stdout without visible sanitization/redaction. Overall: moderate-to-high supply-chain execution risk, with data-leak potential depending on what the previewed component renders.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Aug 19, 2026, 02:01 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fexperience-lwc-runtime-observe%2F@b0cb086af7c36751bf858ab04efb2e9090bdb9eaec7dfcbbd5572745432d41c2
Security Audit — socket — experience-lwc-runtime-observe