astro

Warn

Audited by Socket on Sep 11, 2026

1 alert found:

Anomaly
AnomalyLOW
evals/files/search-panel.jsx

The code does not show intentional malware, credential theft, obfuscation, or direct code injection. It contains a significant logic and availability issue because the effect updates values included in its own dependency array, causing repeated fetches. The caller-controlled endpoint may also permit unintended client-side data transmission if endpoint is not trusted. React's normal escaping mitigates direct XSS through r.title.

Confidence: 99%Severity: 55%
Audit Metadata
Analyzed At
Sep 11, 2026, 03:15 PM
Package URL
pkg:socket/skills-sh/lynricsy%2Fhyperskills%2Fastro%2F@5c3a8718ec828ff0dfdfe3ad689fe6b30c612a26322070677fcbd35765fe04c7
Security Audit — socket — astro