visual-explainer

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/preview.mjs

No clear evidence of covert malware (no exfiltration, no persistence, no obfuscation, no dynamic code execution from inputs via eval). However, the module has high-impact functionality: it detects an owning package.json and executes its publish/export/build script via spawn during rebuild. If an attacker can influence or swap the target HTML’s owning project/package.json, this becomes a command-execution vector. Given localhost-only server and strong mutation guards, exposure is limited, but the design choice to execute package scripts is the primary supply-chain/sandboxing risk to review.

Confidence: 74%Severity: 55%
Audit Metadata
Analyzed At
Aug 24, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/theclaymethod%2Fartifacture%2Fvisual-explainer%2F@ba55230f7f4461038f7c3d248d79acd04f085ea8f5a191b3b69a1bfca7038ce9
Security Audit — socket — visual-explainer