browse
Audited by Socket on Oct 2, 2026
8 alerts found:
Securityx5Anomalyx3No direct malware behavior is evident. The principal security concern is mutable token objects: callers receiving a token from createToken() can alter its clientId or scopes and affect authorization, including impersonating root. restoreRegistry() also trusts authorization fields in supplied state, so restored data must be trusted and protected. Rate-limit validation permits NaN, which can disable the intended limit.
No clear evidence of stealthy malware, cryptomining, or covert network exfiltration is present in the provided snippet. However, the module provides a high-privilege “arbitrary JS evaluation” capability ('js' and 'eval') and can persist results to disk ('--out' -> fs.writeFileSync). If any untrusted party can invoke these commands or influence expressions/paths, this presents a significant security risk (DOM/cookie data access and potential arbitrary file write depending on validateOutputPath/validateReadPath). Overall risk is driven by capability exposure rather than overt malicious payloads.
The code implements Playwright stealth and browser-fingerprint spoofing, including removal of automation indicators. This is intentional evasion behavior and may violate target-site policies, but the fragment provides no evidence of malware, data theft, or system compromise. Environment-derived launch values are passed as arguments rather than shell commands.
This code is not obviously malware by itself (no obfuscated payloads or direct exfiltration logic), but it is a high-impact supply-chain execution harness that runs skill-provided TypeScript/JS via Bun. The biggest concrete security issue in this fragment is that the test path forwards the full, unfiltered parent process.env to the spawned test process, while the run path only partially filters environment variables. Additionally, “trusted” mode forwards nearly all environment variables to child code, and untrusted-mode secret filtering is heuristic. Overall, the trust boundary is strong, and if any skill/test content is untrusted or can be tampered with, sensitive-data exposure or misuse of minted tokens becomes plausible.
No direct malware or automated data exfiltration is implemented in this HTML snippet (no JavaScript/network calls). However, it contains multiple high-risk social-engineering/prompt-injection strings—some hidden/off-screen and some in ARIA/visible text—explicitly attempting to coerce token/session disclosure and visits to attacker-controlled endpoints. This should be treated as hostile content in any rendering pipeline, especially where AI assistants or automated agents interpret page text as instructions.
No malicious executable code is present in the HTML fragment, but the content is highly suspicious: it directly encourages users to share API keys/tokens, session details, and environment variables with an external support channel/portal. Treat this as a credential-harvesting/social-engineering risk and do not follow the instructions.
This module is a static HTML page with multiple concealed instruction-like strings (including a malicious aria-label) attempting to coerce navigation to attacker-controlled URLs and cookie/token exfiltration. However, the snippet contains no JavaScript or implemented network/system actions, so it does not itself perform malware behavior. The security risk is primarily social-engineering/content-smuggling that could influence downstream processing or user/tool actions outside this file.
The code deliberately creates a detached, persistent child process, records its PID, and can terminate the parent process. This can cause resource leakage or process disruption if invoked, though the API shape and explicit `worker-crash` mode are consistent with a test or crash-simulation fixture. No evidence of data theft or network-based malware is present in this fragment.