rebelle

Warn

Audited by Socket on Aug 3, 2026

1 alert found:

Anomaly
AnomalyLOW
references/websocket.md

No malware implementation details are present in the provided fragment (it is protocol/behavior documentation rather than package code). However, it documents a powerful local WebSocket control surface with high-impact effects: remote interactive manipulation of live artwork and an export_canvas command that writes to a client-supplied absolute filename. The primary security risk arises from exposure/misconfiguration (allowlist/loopback assumptions) rather than evidence of covert malicious behavior. If this capability is properly loopback-restricted and filenames are not abused, risk is reduced.

Confidence: 40%Severity: 52%
Audit Metadata
Analyzed At
Aug 3, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/jablonkai%2Fskills%2Frebelle%2F@4da18489673c520987596952d412eeebe383351ed4ecd4704d265592625509f9
Security Audit — socket — rebelle