processon-diagram-generator
Warn
Audited by Socket on Aug 19, 2026
1 alert found:
AnomalyAnomalysetup.mjs
LOWAnomalyLOW
setup.mjs
No clear, direct evidence of intentional sabotage/malware is visible in this fragment. The primary security concerns are supply-chain execution (runtime `npm install -g mcporter@...`) and credential handling/exfil risk: bearer tokens are stored locally, written into `mcporter` config, and sent via HTTP Authorization headers to `config.mcpUrl` (including through a spawned `node -e` subprocess). If `config` values or token sources can be influenced, this could enable credential leakage. Additional review is needed for the unseen parts (e.g., run(), spawn(), saveLocalToken(), filesystem paths, and how `config` is populated).
Confidence: 55%Severity: 62%
Audit Metadata