wix-headless-replatform

Warn

Audited by Socket on Aug 27, 2026

3 alerts found:

Anomalyx3
AnomalyLOW
scripts/lib/browser-tooling.mjs

The fragment appears to be a legitimate dependency and Playwright environment remediation utility, not malware. Its main security weakness is unsafe shell execution: dynamically constructed installation commands are passed to a shell without escaping or argument arrays. Inputs should be validated and commands should use spawn with shell:false and separated arguments. Automatic installation also inherently trusts package-manager lifecycle scripts. No direct data theft, persistence, destructive behavior, or suspicious exfiltration is present.

Confidence: 93%Severity: 58%
AnomalyLOW
scripts/generate-visual-assets.mjs

This is a build/documentation utility for materializing captured visual assets. It does not show evidence of intentional malware. The primary security issue is an unsafe trust boundary: untrusted inline SVG or symbol markup is written into a potentially web-served public directory without sanitization, which can create stored XSS or active-content risks. The destructive recursive deletion is expected for regeneration but should be constrained by validated output-path handling.

Confidence: 97%Severity: 55%
AnomalyLOW
resources/rp-qa-gap-loop/SKILL.md

SUSPICIOUS: the skill’s purpose and capabilities are mostly aligned with frontend QA automation, and there is no explicit credential harvesting or third-party proxying. However, the named local executables and overall runtime trust path are not publicly verifiable from the supplied evidence, and the skill grants broad autonomous build/fix/review authority, so it carries medium security risk despite lacking strong malware indicators.

Confidence: 82%Severity: 56%
Audit Metadata
Analyzed At
Aug 27, 2026, 03:38 PM
Package URL
pkg:socket/skills-sh/wix%2Fskills%2Fwix-headless-replatform%2F@cbd95a056acc4e88d4d092b00996bf556d197af9c528aef7c5461879351971cf
Security Audit — socket — wix-headless-replatform