lov-cli2anything
Warn
Audited by Socket on Sep 7, 2026
1 alert found:
AnomalyAnomalysrc/extension-bridge.mjs
LOWAnomalyLOW
src/extension-bridge.mjs
No clear malicious payload or malware behavior is present. The code implements an extension-backed local HTTP proxy. The principal risks are an unauthenticated loopback API, wildcard CORS, unrestricted proxy URLs and request data, forged result submission if identifiers are obtained, and unbounded request-body buffering. URL allowlisting, authentication or per-session tokens, strict Origin validation, result schema validation, and body-size limits are recommended.
Confidence: 98%Severity: 68%
Audit Metadata