accessibility

Warn

Audited by Socket on Sep 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/runtime_a11y/runner/index.mjs

This file is a dynamic local probe/module loader. It is not overtly malicious on its own, but it can execute arbitrary code from a dynamically imported .mjs module determined by an untrusted CLI argument. Because probeId is not allowlisted or constrained to remain within the intended directory, the primary risk is unintended module loading/execution (including potential path traversal) if an attacker can influence probeId and/or available modules/files.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
Sep 24, 2026, 09:17 AM
Package URL
pkg:socket/skills-sh/microsoft%2Fhve-core%2Faccessibility%2F@81736a4ec8ec9b97d37000be6741988abc6b65faa78d0c8d83e6d7e9ea188ca9
Security Audit — socket — accessibility