gsap-scrolltrigger-storytelling

Warn

Audited by Socket on Sep 21, 2026

1 alert found:

Anomaly
AnomalyLOW
demo/index.html

No explicit network exfiltration, credential access, or obvious malware mechanics are visible in the provided fragment. However, the module performs high-risk dynamic execution by decoding a Base64 HTML/JS blob and injecting it directly into an iframe via `srcdoc`, while also injecting runtime script URLs via string replacement and using wildcard `postMessage`. The security posture therefore depends heavily on the integrity of `encodedHtml` and the referenced runtime/assets. Treat this as a meaningful supply-chain/sandbox escape review hotspot rather than clearly benign demo code.

Confidence: 58%Severity: 62%
Audit Metadata
Analyzed At
Sep 21, 2026, 01:29 AM
Package URL
pkg:socket/skills-sh/softwareinfocus%2Fthreejs-skills%2Fgsap-scrolltrigger-storytelling%2F@8f8ed8d9fa34f82abb1b750a1216777730bcbeac9894ae6589ab92ce5f15ec3e
Security Audit — socket — gsap-scrolltrigger-storytelling