render-search-grid

Warn

Audited by Socket on Aug 14, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/build_html.py

No clear evidence of intentional malware (backdoor/reverse shell/credential theft) in this fragment. However, the module has a high-impact security risk when the JSON config is not fully trusted: it can read and embed arbitrary local files into the generated HTML (including potential directory traversal via unconstraint of relative paths) and it injects config-derived strings into HTML without robust escaping, including usage of typed.innerHTML with config-driven content. Treat the tool/workflow as a potential local file disclosure/exfiltration generator and require strict controls on config and referenced paths.

Confidence: 72%Severity: 78%
Audit Metadata
Analyzed At
Aug 14, 2026, 05:22 AM
Package URL
pkg:socket/skills-sh/gooseworks-ai%2Fgoose-skills%2Frender-search-grid%2F@80e7006a6bfe9ee965cfb06accef69af685adc193d8becfb9284ac56d8f234a5
Security Audit — socket — render-search-grid