atscript-ui-forms

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
references/dynamic-fields.md

No direct malicious payload is present in the provided fragment, but it documents an intentionally powerful, unsandboxed dynamic execution mechanism (annotation string -> new Function -> host-scope execution) that can drive UI/security-relevant behavior and even write computed values back into the model. The dominant risk is arbitrary code execution if trust in @ui.form.fn.* / @ui.form.validate strings is ever violated.

Confidence: 66%Severity: 80%
Audit Metadata
Analyzed At
May 13, 2026, 01:07 PM
Package URL
pkg:socket/skills-sh/moostjs%2Fatscript-ui%2Fatscript-ui-forms%2F@138ccb5fdbec089b0670d4e793c2de385b54dfcf