add-dashboard

Warn

Audited by Socket on Aug 30, 2026

1 alert found:

Security
SecurityMEDIUM
resources/dashboard-pusher.ts

No clear signs of overt malware behavior (e.g., command execution, remote payload loading, or non-local network targeting) are present in this module. However, it is explicitly designed to collect broad, potentially sensitive internal data—including recent inbound/outbound message records and log excerpts—and repeatedly send it over HTTP to a local dashboard service authenticated with a bearer secret. This is a significant confidentiality/privacy risk if the receiver is untrusted, compromised, or can be spoofed locally, and error suppression reduces observability of the data-export behavior.

Confidence: 66%Severity: 78%
Audit Metadata
Analyzed At
Aug 30, 2026, 02:01 AM
Package URL
pkg:socket/skills-sh/nanocoai%2Fnanoclaw%2Fadd-dashboard%2F@5eeb570347ef477c3d99aa45beed74a850f786525f7c84920aecabfff26d010c
Security Audit — socket — add-dashboard