markdown-mdx-content-pipeline-weapon

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Security
SecurityMEDIUM
examples/next-mdx-blog.md

High-risk construction: the client component evaluates Velite-compiled MDX output via `new Function`, creating an `eval`-like sink from MDX content (`content/posts/*.mdx`) to browser execution. Even if the system intends trusted author content, this is a serious security hazard under threat models involving untrusted/compromised MDX or compromised build tooling; it materially increases the likelihood of client-side compromise and data exposure. No clear explicit malware payload (e.g., network exfiltration) is present in the snippet, but the execution primitive itself is the dominant risk.

Confidence: 76%Severity: 90%
Audit Metadata
Analyzed At
Jul 25, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/jzferrell26%2Fdm-skills%2Fmarkdown-mdx-content-pipeline-weapon%2F@98da4e53a1702a9a71e44fa965d18446f886d537d10f58b766b2b691db67f301
Security Audit — socket — markdown-mdx-content-pipeline-weapon