nocobase-ui-builder

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
runtime/reference-assets/upstream-js/runjs/context/import-async.md

The fragment documents a legitimate dynamic dependency-loading feature and contains no direct evidence of malware. Its main security concern is architectural: arbitrary external ESM and CSS resources are trusted and executed or injected at runtime, with the default source being esm.sh. Production deployments should restrict permitted origins, pin and verify dependencies where possible, use a trusted/self-hosted CDN, and treat loaded modules as fully privileged application code. The frappe-gantt HTML interpolation should also be escaped or restricted when task data is untrusted.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 14, 2026, 06:50 PM
Package URL
pkg:socket/skills-sh/nocobase%2Fskills%2Fnocobase-ui-builder%2F@62f0b3ce78fcdf3f002605fb0961780a69b30553ffb3e5ecbff1e76b8d3d3cc7
Security Audit — socket — nocobase-ui-builder