javascript-pro

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
references/node-essentials.md

No overt malicious behavior (e.g., exfiltration, reverse shells, crypto-mining, credential theft, obfuscated payloads) is evident in the provided fragment. The primary risk is operational/supply-chain execution surface: it directly executes shell commands and spawns a local Node script artifact using a relative working directory with inherited environment. Combined with weak HTTP hardening (permissive CORS and unhandled JSON.parse on untrusted input), this warrants deeper review of any executed scripts and surrounding package lifecycle hooks. Confidence is limited because the contents of the spawned local script (and cleanup()) are not included.

Confidence: 52%Severity: 58%
Audit Metadata
Analyzed At
Aug 27, 2026, 11:50 AM
Package URL
pkg:socket/skills-sh/seltherpython%2Fopencode-skills%2Fjavascript-pro%2F@e2a915e5b74c471c1e0d2fc1d3e15c490fbff2b59a05a0135090ea13fafe423b
Security Audit — socket — javascript-pro