wxa-skills-eval
Warn
Audited by Socket on Jul 7, 2026
1 alert found:
SecuritySecurityassets/report_template.html
MEDIUMSecurityMEDIUM
assets/report_template.html
Overall, this module is a browser-only report renderer with a high-impact DOM XSS risk due to unsanitized insertion of plugin-provided HTML (tab.html) into the DOM via innerHTML. Additionally, it frequently builds HTML from untrusted evaluation data, uses inline onclick patterns (amplifying XSS impact if escaping fails in any branch), loads attacker-controlled snapshot image URLs via img src (tracking/privacy), and exports potentially sensitive evaluation/tool content into downloadable markdown artifacts. Malware likelihood is low in this fragment; primary concern is DOM XSS and data exposure.
Confidence: 78%Severity: 75%
Audit Metadata