gov-overseas-trip-report

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Security
SecurityMEDIUM
tests/fixtures/open-portal.html

No strong evidence of intentional malware, backdoor behavior, or supply-chain compromise is visible in this fragment. However, the code exhibits a high-confidence DOM XSS risk: it concatenates server-provided fields directly into HTML (including data-* attributes) and inserts the result into the DOM with .append(str), and it also generates inline javascript: href links using server-derived parameters. This should be treated as a serious security flaw requiring robust output encoding and removal of javascript: links with safe event binding.

Confidence: 74%Severity: 78%
Audit Metadata
Analyzed At
Sep 17, 2026, 07:50 AM
Package URL
pkg:socket/skills-sh/nomadamas%2Fk-skill%2Fgov-overseas-trip-report%2F@838bed117c58b88bdb344ba9e22d046a43f414cef02a54779cd4c4640c6f4489
Security Audit — socket — gov-overseas-trip-report