sg-record

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
lib/recorder-toolbar.js

This module functions as a client-side session/action recorder. It captures broad interaction and form-related data (including arbitrary non-password input values, clicked UI text, select choices, file-name metadata, and navigation URLs), converts them into replayable selectors/steps, and exports them via bridge({type:'stop', steps}). While it does not show classic malicious payloads (no network/dom/exec primitives in the fragment), the bridge() export of rich user/session data creates a significant privacy and security risk unless strictly controlled with explicit user consent, tight scoping, and robust handling/redaction in the surrounding code.

Confidence: 62%Severity: 72%
Audit Metadata
Analyzed At
Apr 28, 2026, 01:37 PM
Package URL
pkg:socket/skills-sh/bacoco%2FShipGuard%2Fsg-record%2F@0fcc2fe32bcaa90d37c7183384b2c3ff5aad7089