chrome-extension

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/ui-render-with-cached-data.md

The code implements a legitimate cache-first popup rendering pattern and contains no clear malware or supply-chain backdoor behavior. However, it unsafely interpolates remote and cached data into innerHTML. data.status should be validated and escaped, or rendered with textContent and controlled DOM APIs; class names should be selected from an allowlist. The security issue is a meaningful injection risk, not evidence of intentional malicious behavior.

Confidence: 98%Severity: 62%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:50 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fchrome-extension%2F@11b479f95b04b5230639be7268052b6d69c322a6f98d0b8f28ccbfa7723e232e
Security Audit — socket — chrome-extension