dev-rfc

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
assets/marked.min.js

The visible code is a legitimate Markdown lexer/parser/HTML renderer and shows no evidence of malicious supply-chain behavior. The principal security concern is application-level XSS risk: raw HTML is intentionally passed through, and URL encoding alone may not reject dangerous schemes. Untrusted Markdown should be sanitized and link/image protocols should be allowlisted before browser rendering.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:49 AM
Package URL
pkg:socket/skills-sh/pproenca%2Fdot-skills%2Fdev-rfc%2F@cfe7a4783c29204a5d177e3865573bca232b19e6d6d7fda86fb55c280344fa5a
Security Audit — socket — dev-rfc