asset-manager

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/font-management.md

The code is intended to convert local TTF/OTF fonts and configure browser font loading. It contains no clear malicious behavior, but the use of shell-based exec with unescaped input paths is a substantive command-injection vulnerability when the input directory or its filenames are attacker-controlled. Use execFile or spawn with argument arrays, validate paths, and verify regular files before conversion.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 15, 2026, 11:51 AM
Package URL
pkg:socket/skills-sh/oakoss%2Fagent-skills%2Fasset-manager%2F@609e946defdf33c2d0c0147d9e6571c8a1bea08fd70119755b39b1704dd8ed34
Security Audit — socket — asset-manager