service-concierge-portal-generate

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
references/portal-deploy-runbook.md

No clear evidence of traditional supply-chain malware (no obfuscation-driven payloads, no exfiltration, no backdoor/persistence mechanisms) is present in the provided fragment. However, the code intentionally performs high-impact security posture weakening on the deployed Experience Cloud site by disabling Locker, enabling relaxed CSP, and setting clickjacking protection to allow all framing. This materially increases the attack surface and should be treated as a significant security-risk configuration change that must be strictly scoped to only the required sites/conditions and validated to apply only to intended org targets. Overall: low likelihood of malware, elevated security risk due to deliberate browser-defense reduction.

Confidence: 62%Severity: 67%
Audit Metadata
Analyzed At
Aug 27, 2026, 04:35 PM
Package URL
pkg:socket/skills-sh/forcedotcom%2Fsf-skills%2Fservice-concierge-portal-generate%2F@e0a553d25922fc942a4acfa34fef1bc41356e18c
Security Audit — socket — service-concierge-portal-generate