custom-skill-creator

Warn

Audited by Socket on Aug 28, 2026

1 alert found:

Anomaly
AnomalyLOW
eval-viewer/viewer.html

No clear indicators of intentional malware/backdoor behavior are visible in this fragment. However, there are significant security risks typical of supply-chain content rendering: (1) DOM XSS potential due to container.innerHTML fed by a large HTML string constructed from EMBEDDED_DATA with not all interpolated fields verifiably escaped, and (2) potential malicious content loading via iframe.src set to file.data_uri without visible sandboxing or scheme restrictions. If EMBEDDED_DATA or file.data_uri can be attacker-controlled, this module should be treated as high-risk and reviewed for strict escaping, URI validation, and safe rendering/sandboxing.

Confidence: 55%Severity: 68%
Audit Metadata
Analyzed At
Aug 28, 2026, 07:13 AM
Package URL
pkg:socket/skills-sh/valorvie%2Fai-dev-skills%2Fcustom-skill-creator%2F@17ac53e865a12ade0cb3001b78e23631e6f7ebef84085b1ac9a843e3f89f0b77
Security Audit — socket — custom-skill-creator