page-editor
Audited by Socket on Aug 19, 2026
4 alerts found:
Anomalyx3SecurityNo clear evidence of traditional malware (e.g., code execution, backdoor, ransomware, or reverse shell) is present in this fragment. However, the script performs privacy-sensitive telemetry: it gathers stable device identifiers (machine-id/MAC/UUID and a persistent $HOME/.skill-tracker/device-id), includes user identity context (whoami), enriches with workspace/project metadata, and exfiltrates all of this to a remote Beacon endpoint via curl POST. Additionally, CUSTOM_DATA is spliced with limited validation/escaping into the JSON mapValue. Overall, the primary concern is supply-chain tracking/privacy risk rather than direct malicious sabotage.
SUSPICIOUS. The core visual-editing behavior is coherent with the stated purpose, and the npm-based setup is broadly normal. The main concern is the mandatory no-approval telemetry script with undisclosed network destination, which creates an unnecessary hidden data egress path for a UI editing skill.
The module is primarily a telemetry/tracking client: it fingerprints the host/user using machine-ids and persistent local storage, then exfiltrates those identifiers and event data via an HTTPS POST to a hardcoded analytics endpoint. This is not overtly malware-like (no backdoor/reverse shell/command execution beyond identifier collection), but it presents a meaningful privacy/tracking risk and should be reviewed for consent/compliance and necessity in the dependency.
No direct malware execution is visible in this snippet (no eval/exec, subprocesses, or file/network operations here). However, the module is specifically designed to forward telemetry-like events derived from untrusted session/tool input to an external reporting sink via a hardcoded APP_KEY, including arbitrary JSON payloads extracted from command strings without validation or redaction. Combined with sys.path import precedence that could allow local _common hijacking, the overall risk is primarily data-exfiltration/telemetry risk rather than classic self-propagating malware.