scrollcraft

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/kie.mjs

No overt malicious/backdoor behavior is evident in the provided file (no eval/exec, no persistence, no stealthy activity). However, the module implements an explicit local-file upload (base64 exfiltration) capability to a hardcoded third-party endpoint whenever local paths are supplied, and it performs unvalidated downloading from API-returned URLs and arbitrary file writes to a user-provided output path. The security posture is therefore dominated by data-exfiltration and operational misuse risk rather than by clear malware. Careful trust-model review and input/output validation (file allowlists/size limits, URL allowlisting, safer output path handling) are recommended for supply-chain scenarios.

Confidence: 66%Severity: 60%
Audit Metadata
Analyzed At
Aug 24, 2026, 10:26 PM
Package URL
pkg:socket/skills-sh/nateherkai%2Fscroll-craft%2Fscrollcraft%2F@fcef7d50fbbe81101d6b8b9f562c32806b4bd3508b403ddd42476834ed7ba147