pixel-by-pixel

Warn

Audited by Socket on Jul 23, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/lib/runtime-attempts.mjs

This module is a high-impact browser capability interception layer that records URL/RTC/service-worker related metadata and can block network/real-time and service-worker operations when blockEffects is enabled. No explicit malicious payload behavior (e.g., code execution, direct exfiltration, credential theft) is visible in the fragment, but the combination of sensitive API tampering and unknown record(...) handling creates a meaningful supply-chain privacy/security risk that requires review of record(...), urlText(...), and surrounding enforcement logic.

Confidence: 60%Severity: 55%
Audit Metadata
Analyzed At
Jul 23, 2026, 07:11 PM
Package URL
pkg:socket/skills-sh/L4A-ai%2Freplicate-websites%2Fpixel-by-pixel%2F@4d7213bef4dc91ef19ba1d01510f6792ff9ea6fcbc6599b7b13d2a63bdc9a780
Security Audit — socket — pixel-by-pixel