wix-docs-base44

Warn

Audited by Socket on Aug 19, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
scripts/disk.js

This module primarily performs documentation retrieval and markdown parsing with optional local caching. It does not show overt backdoor/exfiltration/malware behavior in the provided fragment. However, it contains significant security weaknesses if callers can control inputs: (1) SSRF-like behavior via caller-influenced URL fetching (resolveRef/post), (2) potentially unsafe filesystem writes to SCRATCH using a caller-influenced filename without robust path sanitization/containment enforcement, and (3) dynamic RegExp construction from untrusted strings that can lead to ReDoS or incorrect matching. Treat it as a utility that should be sandboxed and have strict input allowlists if used in a security-sensitive context.

Confidence: 66%Severity: 62%
AnomalyLOW
scripts/docs.js

No clear evidence of classical malware in this fragment. However, it contains a high-impact supply-chain/sandbox trust risk: it delegates dynamically generated and caller-provided JavaScript code strings to a remote SPEC_API via post({code: ...}), and it also provides a generic authenticated fetch that can target arbitrary caller-supplied URLs with a bearer token. These patterns warrant strict input validation, strong sandboxing/whitelisting on the SPEC_API side, and URL/token allowlisting or network egress controls to prevent SSRF and credential exfiltration.

Confidence: 62%Severity: 63%
AnomalyLOW
bootstrap.md

This fragment itself does not show explicit malware behavior (no clear theft/exfiltration/backdoor logic), but it performs a runtime supply-chain installation using execSync + npx and then instructs loading and following code from the installed skill directory (scripts/docs.js). Because the downstream installed content is not included, the security risk should be treated as moderate due to execution of unverified external code during installation and implied execution during STEP 1.

Confidence: 63%Severity: 55%
Audit Metadata
Analyzed At
Aug 19, 2026, 03:12 PM
Package URL
pkg:socket/skills-sh/wix%2Fskills%2Fwix-docs-base44%2F@76e2e4fa5accc884c80cb25a996e9e3682c23869f2ddbfd970511758c7550e9d
Security Audit — socket — wix-docs-base44