wiki-viewer

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/render.js

No clear evidence of intentional malware behavior (no network/exfiltration/backdoor mechanics shown). The primary security issue is stored XSS: the client-side code injects page.html directly into the DOM using innerHTML without sanitization in this fragment. If page.html can contain attacker-controlled HTML/JS (e.g., from untrusted wiki authors or unsafe upstream conversion), opening the generated viewer.html and navigating to a page can execute arbitrary script in the viewer context. Additional lower-impact risks include clipboard manipulation and potential output-path misuse if CLI/path inputs are not controlled.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Sep 14, 2026, 07:50 PM
Package URL
pkg:socket/skills-sh/rohitg00%2Fpro-workflow%2Fwiki-viewer%2F@465fc87d7b55b592e7215e31889d582098111330f9befb2ba3f6c95bab906779
Security Audit — socket — wiki-viewer