number-details

Warn

Audited by Socket on Jul 25, 2026

1 alert found:

Anomaly
AnomalyLOW
demo/index.html

This module is primarily a client-side sandbox/demo loader that decodes an embedded base64 HTML payload and executes it via iframe.srcdoc. It also fetches local media assets, base64-encodes them, and delivers them to the iframe via postMessage using a wildcard origin. No explicit credential theft or network exfiltration is visible in the snippet alone, but the combination of runtime-decoded HTML injection and wildcard postMessage is a meaningful security risk indicator. To determine whether it is genuinely benign, the decoded contents of encodedHtml and the iframe element attributes/receiver message handlers must be reviewed.

Confidence: 62%Severity: 58%
Audit Metadata
Analyzed At
Jul 25, 2026, 05:39 AM
Package URL
pkg:socket/skills-sh/MengTo%2FSkills%2Fnumber-details%2F@5fb3302782bf8511fbbbc3b32985acfb9bf16b0d8865ae9b8e46a048b5b5d163
Security Audit — socket — number-details