template-creator
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyscripts/main.cjs
LOWAnomalyLOW
scripts/main.cjs
The code appears to be a legitimate local template-generation CLI, with no clear malware indicators. The main security issue is insufficient validation of the user-controlled category path, which can enable path traversal or writes outside the intended templates directory. Markdown metadata injection is also possible. Restrict category to a safe path segment and verify the resolved path remains under TEMPLATES_DIR before creating or writing files. If the displayed fragment is complete, it also contains a syntax error due to missing closing braces.
Confidence: 98%Severity: 55%
Audit Metadata