syncfusion-angular-inline-ai-assist

Warn

Audited by Socket on Sep 17, 2026

1 alert found:

Anomaly
AnomalyLOW
references/core-configuration.md

The code contains no apparent malware or supply-chain sabotage. It is configuration/documentation with ordinary AI UI behavior. Security review is warranted because AI or persisted response content is inserted directly into innerHTML, creating a potential XSS sink, and the frontend OpenAI example could expose an API key if used literally. Conversation persistence in localStorage may also disclose sensitive prompts and responses to same-origin scripts.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 02:23 AM
Package URL
pkg:socket/skills-sh/syncfusion%2Fangular-ui-components-skills%2Fsyncfusion-angular-inline-ai-assist%2F@01e7cb59ad63869a175b05bb9d17a5f7fd15f39d7b24f7431b9b1566df2a5106
Security Audit — socket — syncfusion-angular-inline-ai-assist