motion-doctrine

Warn

Audited by Socket on Jul 16, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/seam-stamp.mjs

No explicit malicious payload (exfiltration, persistence, or network activity) is present in this module. However, it is a powerful code generator that embeds unescaped ledger-controlled selector values into executable JavaScript and can write modified HTML/JS to an arbitrary path supplied via --write. If an attacker can control the ledger content and/or CLI paths, the most significant threats are JavaScript injection into the output asset and unauthorized file read/write within the runner’s permissions.

Confidence: 74%Severity: 62%
Audit Metadata
Analyzed At
Jul 16, 2026, 09:31 PM
Package URL
pkg:socket/skills-sh/heygen-com%2Fhyperframes%2Fmotion-doctrine%2F@623ee3fda8adbc088ca90054fae6f2db53194a4c55d3738d9f45b13dacea5ce9
Security Audit — socket — motion-doctrine