interact

Warn

Audited by Socket on May 12, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/interact-server.js

No clear indicators of deliberate malware (no backdoor, no process/network exfiltration to external domains, no crypto-mining, no command execution besides spawning the intended server). However, there is a significant security flaw: user-controlled interaction IDs from HTTP requests/URLs are used directly in filesystem paths for reading and writing JSON files, enabling path traversal and arbitrary file read/write relative to the project root (depending on OS/path.join behavior and the chosen root). This is the primary supply-chain/security concern for this module.

Confidence: 78%Severity: 72%
Audit Metadata
Analyzed At
May 12, 2026, 08:23 PM
Package URL
pkg:socket/skills-sh/m00nlygreat%2Fpicky-ux-skills%2Finteract%2F@f1847b21fcd10aa7d479eb6d89ef79cf772a57c8