chart
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalyscripts/build_chart.py
LOWAnomalyLOW
scripts/build_chart.py
The code is a chart-generation and file-output utility with no clear malicious behavior. The primary security concerns are unvalidated filesystem paths and unsanitized HTML, CSS, and JavaScript interpolation, which can cause path traversal or stored/browser-side code execution when inputs are untrusted. The empty page.evaluate() call is a likely implementation bug. The external ECharts CDN is a supply-chain/runtime dependency but is not by itself malicious.
Confidence: 98%Severity: 52%
Audit Metadata