majia-guanyuan

Warn

Audited by Socket on Jul 3, 2026

2 alerts found:

SecurityAnomaly
SecurityMEDIUM
SKILL.md
AnomalyLOW
templates/html-dashboard/charts/html_trend.js

No direct malicious actions (exfiltration, credential theft, or network activity) are evident in this module’s chart-rendering logic. The primary security concern is the supply-chain/backdoor-style pattern of executing a dynamically loaded JavaScript text asset at runtime via new Function(__gdHtmlCommon)(). The overall risk therefore depends heavily on the integrity and contents of ./html_common.js and on how GDHTML.lineSvg/stacked safely handle data-derived values when generating SVG/HTML.

Confidence: 55%Severity: 60%
Audit Metadata
Analyzed At
Jul 3, 2026, 02:47 PM
Package URL
pkg:socket/skills-sh/maojiebc%2Fguanyuan-majia%2Fmajia-guanyuan%2F@3ef26e62fec108c09338991f0b7bbb0e57b60467
Security Audit — socket — majia-guanyuan