architecture-canvas

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/validate.js

This module is primarily a geometry/schema validator, but it executes the provided scene.js file using new Function, making it an arbitrary code execution primitive if the scene content or path is attacker-controlled. Aside from that evaluation sink, the rest of the code performs only local consistency checks and logs diagnostics, with potential log-content reflection. If scene.js is fully trusted, the remaining risk is substantially lower; if not, treat this as high risk for supply-chain/entry-point compromise.

Confidence: 86%Severity: 92%
Audit Metadata
Analyzed At
Aug 19, 2026, 03:49 PM
Package URL
pkg:socket/skills-sh/yulonghe97%2Fdraw-architecture%2Farchitecture-canvas%2F@e7ff34758730f7822f8aedf7a37e3c5c0e0ac204
Security Audit — socket — architecture-canvas