app-preview-craft
Audited by Socket on Sep 23, 2026
2 alerts found:
Anomalyx2The fragment is consistent with a local preview/rendering studio, not malware. It contains meaningful security concerns if the HTTP server is exposed to untrusted clients: notably an insufficiently constrained render output path, weak reveal-path containment, lack of visible authentication, and unrestricted JSON/resource handling. The process spawning is platform opener functionality and does not itself indicate malicious intent.
The fragment appears to be legitimate browser-side stage/rendering code, not malware. Its main security issue is insecure cross-window messaging: commands are accepted without origin validation and responses use wildcard target origins. Untrusted specifications can also influence external asset requests and rendering-related DOM styles. These issues should be addressed if the stage can be embedded or reached by untrusted windows, but the fragment contains no clear malicious behavior.