baoyu-markdown-to-html

Warn

Audited by Socket on Aug 21, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/main.ts

No clear indicator of intentional malware/backdoor behavior in this module. However, it presents meaningful security risk when processing untrusted Markdown: it can download arbitrary http/https resources referenced in Markdown (including following redirects, without host/IP restrictions), it executes external tooling via spawnSync('npx', ...) with environment/tooling trust dependencies, and it injects unescaped local path strings into HTML attributes, creating potential HTML/attribute injection risks in the generated HTML. Review/limit input trust, restrict remote URL handling, and escape/encode HTML attribute values.

Confidence: 70%Severity: 65%
Audit Metadata
Analyzed At
Aug 21, 2026, 02:10 AM
Package URL
pkg:socket/skills-sh/spacezephyr%2Fmyskill%2Fbaoyu-markdown-to-html%2F@ac7209b3533385cf6cf8d790ab285a18f7a7afdd272969fec3bbc1485b0110a0