rebelle
Warn
Audited by Socket on Aug 3, 2026
1 alert found:
AnomalyAnomalyreferences/websocket.md
LOWAnomalyLOW
references/websocket.md
No malware implementation details are present in the provided fragment (it is protocol/behavior documentation rather than package code). However, it documents a powerful local WebSocket control surface with high-impact effects: remote interactive manipulation of live artwork and an export_canvas command that writes to a client-supplied absolute filename. The primary security risk arises from exposure/misconfiguration (allowlist/loopback assumptions) rather than evidence of covert malicious behavior. If this capability is properly loopback-restricted and filenames are not abused, risk is reduced.
Confidence: 40%Severity: 52%
Audit Metadata