mockup-lab
Audited by Socket on Aug 26, 2026
2 alerts found:
Anomalyx2The fragment is primarily a design-generation and visual-review utility, not clear malware. It does read local project files and API credentials and is designed to send gathered context and images to model services. Unrestricted reference URL fetching and arbitrary file inclusion create meaningful privacy and supply-chain risks. The hardcoded development-style key should be removed or rotated if valid. Because the code is truncated and the actual request implementation is missing, the assessment of external data transmission is based partly on visible constants and surrounding request construction. No direct destructive behavior, shell execution, persistence, or reverse shell is demonstrated.
The script appears to be a legitimate API-driven UI tooling wrapper, not malware. Its main security concerns are runtime installation of an unpinned npm dependency, exposure of the Gemini key in a URL, transmission of potentially sensitive images/specifications to Google, and unsafe interpolation of specification text into dynamically generated Python code. Review the delegated Node.js and Python files separately before trusting the complete toolchain.