chart

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/build_chart.py

The code is a chart-generation and file-output utility with no clear malicious behavior. The primary security concerns are unvalidated filesystem paths and unsanitized HTML, CSS, and JavaScript interpolation, which can cause path traversal or stored/browser-side code execution when inputs are untrusted. The empty page.evaluate() call is a likely implementation bug. The external ECharts CDN is a supply-chain/runtime dependency but is not by itself malicious.

Confidence: 98%Severity: 52%
Audit Metadata
Analyzed At
Sep 15, 2026, 10:06 AM
Package URL
pkg:socket/skills-sh/starchild-ai-agent%2Fofficial-skills%2Fchart%2F@02102830f23575042abda9d2b22c3859c12daaf05e77832cae02e574a1624eec
Security Audit — socket — chart