legal-diagram

Warn

Audited by Socket on Jul 30, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/fetch_mermaid.py

This module is not overtly malicious in isolation; it functions as a vendoring/downloader. However, it introduces a meaningful supply-chain risk by downloading third-party JavaScript from a CDN and writing it to disk without cryptographic integrity verification, relying only on a minimum file-size check. Additionally, the ability to influence the destination path via --dest raises a potential arbitrary file write risk unless upstream constraints ensure dest stays within the intended vendor directory.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
Jul 30, 2026, 07:41 PM
Package URL
pkg:socket/skills-sh/lawve-ai%2Fawesome-legal-skills%2Flegal-diagram%2F@7ef03ce1b7336d4371a19d6eb487ad9ec23c2d3e988d7b87236c84a0ab4d7d0e
Security Audit — socket — legal-diagram