running-code-analyzer

Warn

Audited by Socket on May 29, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/apply-fixes.js

This module is not overtly malware (no networking, execution, or persistence). However, it is a high-impact file patching tool that fully trusts an external JSON file to choose target file paths and to insert arbitrary replacement text. If the JSON input is tampered with or attacker-controlled, it can enable arbitrary file read/write within the process permissions and supply-chain style source-code injection that may later be built/executed by downstream tooling.

Confidence: 72%Severity: 74%
Audit Metadata
Analyzed At
May 29, 2026, 02:39 AM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Frunning-code-analyzer%2F@e09ab894cd887a17f764bee86c3cb198b9bd51a2
Security Audit — socket — running-code-analyzer