prd-prototype

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/router_generator.js

The code appears to be a benign navigation and router code generator, with no evidence of malware or supply-chain sabotage. It has input-handling weaknesses: untrusted module names can cause HTML injection/XSS when generated navigation is rendered, and can break or inject code into generated Vue router source. Template keys should be regex-escaped and generated HTML/JavaScript should use context-appropriate escaping. The supplied fragment alone does not perform the dangerous downstream operations.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 16, 2026, 02:04 AM
Package URL
pkg:socket/skills-sh/guoxiangjie%2Fskills%2Fprd-prototype%2F@71c9c2d560b14154379570f538ad488982aef93889fcc72e3c975341e090194b
Security Audit — socket — prd-prototype