figma-playwright-fallback

Warn

Audited by Socket on Jun 19, 2026

1 alert found:

Anomaly
AnomalyLOW
snippets/export-svg-via-panel.js

Overall, the code is best characterized as automated export-and-extraction tooling with a strong instrumentation capability: it globally monkey-patches URL.createObjectURL to capture blob/object URLs and then fetches the exported SVG content for return. No classic malware indicators (external exfiltration, credential theft, code execution) are present in this fragment, but the global blob interception and content harvesting behavior represent a meaningful privacy/data-extraction risk and warrant review/permissioning in a supply-chain context.

Confidence: 74%Severity: 56%
Audit Metadata
Analyzed At
Jun 19, 2026, 07:30 PM
Package URL
pkg:socket/skills-sh/ImL1s%2Fflutter-claude-skills%2Ffigma-playwright-fallback%2F@d803e2f2ba8d490162502f257ec79b6d986139989a39cdb3acc91c782d1fe5c5
Security Audit — socket — figma-playwright-fallback