wxa-skills-eval

Warn

Audited by Socket on Jul 7, 2026

1 alert found:

Security
SecurityMEDIUM
assets/report_template.html

Overall, this module is a browser-only report renderer with a high-impact DOM XSS risk due to unsanitized insertion of plugin-provided HTML (tab.html) into the DOM via innerHTML. Additionally, it frequently builds HTML from untrusted evaluation data, uses inline onclick patterns (amplifying XSS impact if escaping fails in any branch), loads attacker-controlled snapshot image URLs via img src (tracking/privacy), and exports potentially sensitive evaluation/tool content into downloadable markdown artifacts. Malware likelihood is low in this fragment; primary concern is DOM XSS and data exposure.

Confidence: 78%Severity: 75%
Audit Metadata
Analyzed At
Jul 7, 2026, 09:31 AM
Package URL
pkg:socket/skills-sh/wechat-miniprogram%2Fai-mode-skills%2Fwxa-skills-eval%2F@be62421dc69416e21946d2dde5ec69a1e8ed0085a9fb3419548c4a73b34a1b23
Security Audit — socket — wxa-skills-eval