automation-advisor

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Security
SecurityMEDIUM
templates/index.html

No clear evidence of intentional supply-chain malware or backdoor behavior is present in this snippet. However, the code contains high-impact DOM XSS weaknesses due to unsanitized innerHTML assignments for user/server-controlled strings (chat message content and recommendation items). Additionally, it records microphone audio and uploads it for transcription, which is a significant privacy-sensitive behavior. If recommendations/content are not strictly sanitized server-side, this module presents a serious browser compromise risk.

Confidence: 72%Severity: 74%
Audit Metadata
Analyzed At
Jul 15, 2026, 07:30 AM
Package URL
pkg:socket/skills-sh/glebis%2Fclaude-skills%2Fautomation-advisor%2F@c7029030c8d94741a64597a87ef84f397074f38f299cd17475436120c7486103
Security Audit — socket — automation-advisor