kelly-finance

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Anomaly
AnomalyLOW
content/kelly-finance-app/app/app.js

No clear evidence of overt malware (backdoor, credential theft, exfiltration, reverse shell) appears in this snippet. The primary security concern is DOM XSS potential: dynamic content from snapshot()/checks()/error.message is inserted into the DOM using innerHTML/insertAdjacentHTML without visible escaping. If upstream data can be influenced by an attacker, this module could render/expose malicious HTML/JS. Additionally, user-entered review comments/drafts are submitted to an external provider, so provider-side sanitization and authorization are critical.

Confidence: 65%Severity: 63%
Audit Metadata
Analyzed At
Aug 25, 2026, 10:41 AM
Package URL
pkg:socket/skills-sh/mr-kelly%2Fskills%2Fkelly-finance%2F@94ff0a81880b7eacdc5138549aaa36bf1f7f0cc5115ca55b4430ce6f396d356a
Security Audit — socket — kelly-finance