app-preview-craft

Warn

Audited by Socket on Sep 23, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
scripts/studio.mjs

The fragment is consistent with a local preview/rendering studio, not malware. It contains meaningful security concerns if the HTTP server is exposed to untrusted clients: notably an insufficiently constrained render output path, weak reveal-path containment, lack of visible authentication, and unrestricted JSON/resource handling. The process spawning is platform opener functionality and does not itself indicate malicious intent.

Confidence: 93%Severity: 62%
AnomalyLOW
stage/engine.js

The fragment appears to be legitimate browser-side stage/rendering code, not malware. Its main security issue is insecure cross-window messaging: commands are accepted without origin validation and responses use wildcard target origins. Untrusted specifications can also influence external asset requests and rendering-related DOM styles. These issues should be addressed if the stage can be embedded or reached by untrusted windows, but the fragment contains no clear malicious behavior.

Confidence: 97%Severity: 56%
Audit Metadata
Analyzed At
Sep 23, 2026, 08:08 AM
Package URL
pkg:socket/skills-sh/imshaikot%2Fapp-preview-craft-skill%2Fapp-preview-craft%2F@e801f8258a319f45602508438158cff8b7cfd93866c471d080530ea356d25a83
Security Audit — socket — app-preview-craft