babysit-specs

Warn

Audited by Socket on Sep 12, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
evals/fixtures/queued-specs/src/preferences.js

The code is a DOM rendering helper with a potential DOM-based cross-site scripting vulnerability if channel.label or channel.id can be influenced by untrusted input. Use textContent and setAttribute or DOM properties instead of constructing HTML strings. No evidence of malicious behavior, data theft, obfuscation, or backdoor functionality is present.

Confidence: 99%Severity: 62%
AnomalyLOW
evals/fixtures/queued-specs/server.js

The code is a benign static file server with a path traversal/arbitrary file-read risk because the client-controlled URL is used in filesystem path construction without enforcing that the resolved path remains under the src directory. No clear malicious or supply-chain behavior is present. The issue should be fixed by decoding and normalizing the path, rejecting traversal, and verifying that the resolved path is within the intended root.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 12, 2026, 04:13 PM
Package URL
pkg:socket/skills-sh/toy-crane%2Fskills%2Fbabysit-specs%2F@4ca1896df6be1c93a4591ea0e90d535a751f5ee7baf964e78d4d2f1affbc466b
Security Audit — socket — babysit-specs