story-long-scan

Warn

Audited by Socket on Aug 24, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/cdp-utils.js

No direct evidence of overt malicious behavior (e.g., network exfiltration, persistence, credential theft) exists in this fragment. However, the module intentionally provides an “eval” channel by base64-encoding and forwarding caller-provided JavaScript to a spawned agent-browser, creating a high-impact execution primitive if inputs are not strictly trusted. On Windows, it also resolves execution via PATH-discovered agent-browser.cmd contents, increasing the risk of executing a substituted/malicious wrapper in compromised environments. Treat this module as security-sensitive and enforce strict trust boundaries on js/args and on PATH/executable resolution.

Confidence: 63%Severity: 62%
Audit Metadata
Analyzed At
Aug 24, 2026, 03:18 PM
Package URL
pkg:socket/skills-sh/zenstory-ai%2Foh-story-claudecode%2Fstory-long-scan%2F@ad3a342cee576a8c97a4d809f8b5bcf75ed258be3ed9cdccce645f0a94b46bad
Security Audit — socket — story-long-scan