markdown-novel-viewer

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/lib/plan-navigator.cjs

Likely non-malicious parsing/navigation logic, but it has significant security weaknesses: it directly injects markdown-derived values (e.g., phase names, plan name, next/prev labels) into returned HTML without escaping (high XSS risk). It also resolves markdown-provided file/link targets with `path.resolve` without confining them to the intended directory, which can enable path traversal or unintended file access if the downstream `/view` route does not strictly validate paths.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 29, 2026, 03:19 AM
Package URL
pkg:socket/skills-sh/hotriluan%2Falkana-dashboard%2Fmarkdown-novel-viewer%2F@d0d076cf026d6d5f3abd44318adc941d2529266e