micro-landing-builder
Audited by Socket on Sep 15, 2026
2 alerts found:
Anomalyx2No direct malware behavior is evident. The code is intended as a project scaffolder, but it has a path traversal risk through the unvalidated slug and a supply-chain risk from arbitrary UI package selection and the mutable 'latest' dependency. The fragment is syntactically incomplete or corrupted, so analysis of missing functions is not possible.
The code is a legitimate batch project-generation utility with no clear evidence of malware or intentional sabotage. It has a filesystem path traversal risk because externally supplied slugs are used without normalization or validation, and the outside-directory safeguard is applied only to the root. Validate slugs as safe relative directory names and verify each resolved target remains beneath the resolved root. Review scaffold.py separately because this file executes it and explicitly passes --allow-outside.