shape-idea

Warn

Audited by Socket on Sep 28, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
evals/fixtures/notification-preview/server.js

This is a simple static file server and contains no evidence of malware, credential theft, persistence, or unauthorized network activity. It has a path traversal containment weakness caused by prefix matching, allowing access to certain sibling paths whose names begin with the configured root. Replace the check with a boundary-safe comparison, such as verifying file === root or file.startsWith(root + path.sep), preferably after path.resolve. Binding explicitly to 127.0.0.1 would also reduce unintended exposure for a development server.

Confidence: 98%Severity: 56%
AnomalyLOW
evals/fixtures/notification-settings/server.js

The code appears to be a benign static HTTP file server and contains no clear malware or supply-chain backdoor behavior. It has a potentially exploitable path containment flaw because startsWith(root) is not a reliable directory-boundary check after path traversal normalization. Replace it with path.resolve and a path.relative-based containment check, and avoid serving sensitive files from the document root.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 28, 2026, 01:14 AM
Package URL
pkg:socket/skills-sh/toy-crane%2Fskills%2Fshape-idea%2F@f34a083490ef7ebf4b609d345428d7fd974ace20f57707d82aac7c62a9bfd938
Security Audit — socket — shape-idea