design-builder

Warn

Audited by Socket on May 8, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/preview-server.ts

No strong evidence of intentional malware is visible in this fragment (no external network exfiltration, command execution, or backdoor-like behavior). However, the preview wrapper embeds arbitrary .html content directly into a new HTML document without sanitization, which can enable script execution/XSS-like behavior in the preview context if sessionDir contents or filenames are not fully trusted. Additionally, the /event endpoint persists unvalidated user-controlled JSON to disk, creating an integrity/availability risk via unbounded logging and potential log-content injection.

Confidence: 63%Severity: 62%
Audit Metadata
Analyzed At
May 8, 2026, 07:05 PM
Package URL
pkg:socket/skills-sh/adeonir%2Fagent-skills%2Fdesign-builder%2F@dca9309a2c07d8fa955c30fe98ef4f552adafc4a