beautiful-shadows

Warn

Audited by Socket on Aug 25, 2026

1 alert found:

Anomaly
AnomalyLOW
demo/index.html

The module dynamically decodes an embedded HTML template and injects it into an iframe via `srcdoc`, then loads (optionally) local media assets and passes base64-encoded assets into the iframe using `postMessage` with `targetOrigin='*'`. No explicit credential theft or external exfiltration is evident in the shown fragment, but the encoded-payload + `srcdoc` execution pattern and wildcard messaging are notable security risks that require inspection of the fully decoded HTML and verification of iframe sandboxing and receiver-side origin/type checks.

Confidence: 45%Severity: 55%
Audit Metadata
Analyzed At
Aug 25, 2026, 03:08 AM
Package URL
pkg:socket/skills-sh/yray%2Fskills%2Fbeautiful-shadows%2F@84e344048a5a5cd9de4eb45996ec49b384b9b4e6ad3c54fd1f80972ac9248065
Security Audit — socket — beautiful-shadows