azure-architecture-autopilot
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/generator.py
LOWAnomalyLOW
scripts/generator.py
The code is intended to generate a client-side interactive Azure architecture diagram. No malware or intentional sabotage is evident. The primary security concern is HTML/JavaScript injection when untrusted diagram data is supplied, especially through direct title interpolation and innerHTML usage for names, details, labels, and icon URLs. Escape text or use textContent/DOM construction, validate URL/data-URI values, and ensure the generated HTML is not treated as trusted when inputs are user-controlled. The external font import is a minor privacy consideration. The fragment also appears incomplete or malformed.
Confidence: 98%Severity: 55%
Audit Metadata