page-editor

Warn

Audited by Socket on Aug 19, 2026

4 alerts found:

Anomalyx3Security
AnomalyLOW
scripts/track.sh

No clear evidence of traditional malware (e.g., code execution, backdoor, ransomware, or reverse shell) is present in this fragment. However, the script performs privacy-sensitive telemetry: it gathers stable device identifiers (machine-id/MAC/UUID and a persistent $HOME/.skill-tracker/device-id), includes user identity context (whoami), enriches with workspace/project metadata, and exfiltrates all of this to a remote Beacon endpoint via curl POST. Additionally, CUSTOM_DATA is spliced with limited validation/escaping into the JSON mapValue. Overall, the primary concern is supply-chain tracking/privacy risk rather than direct malicious sabotage.

Confidence: 74%Severity: 62%
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The core visual-editing behavior is coherent with the stated purpose, and the npm-based setup is broadly normal. The main concern is the mandatory no-approval telemetry script with undisclosed network destination, which creates an unnecessary hidden data egress path for a UI editing skill.

Confidence: 89%Severity: 74%
AnomalyLOW
hooks/_common.py

The module is primarily a telemetry/tracking client: it fingerprints the host/user using machine-ids and persistent local storage, then exfiltrates those identifiers and event data via an HTTPS POST to a hardcoded analytics endpoint. This is not overtly malware-like (no backdoor/reverse shell/command execution beyond identifier collection), but it presents a meaningful privacy/tracking risk and should be reviewed for consent/compliance and necessity in the dependency.

Confidence: 72%Severity: 55%
AnomalyLOW
hooks/hooks.py

No direct malware execution is visible in this snippet (no eval/exec, subprocesses, or file/network operations here). However, the module is specifically designed to forward telemetry-like events derived from untrusted session/tool input to an external reporting sink via a hardcoded APP_KEY, including arbitrary JSON payloads extracted from command strings without validation or redaction. Combined with sys.path import precedence that could allow local _common hijacking, the overall risk is primarily data-exfiltration/telemetry risk rather than classic self-propagating malware.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Aug 19, 2026, 05:36 PM
Package URL
pkg:socket/skills-sh/hk-hub%2Fagentskills%2Fpage-editor%2F@43a2ff72ffd891a683778882c9f077ed5dc361d44bffbe7caaf1016ba7c6a634
Security Audit — socket — page-editor