build

Warn

Audited by Socket on May 7, 2026

1 alert found:

Anomaly
AnomalyLOW
starter-kits/video-editor/package.json

This package.json mostly contains normal development and build scripts. The primary security concerns are: (1) postinstall can execute a script located outside the package (../shared/scripts/...), which enables potential untrusted code execution if that external path is writable or controlled by an attacker; and (2) the use of the mutable "latest" tag for @cesdk/cesdk-js increases supply-chain risk. No explicit malicious behaviors (reverse shells, telemetry uploads, http-based dependencies, or overrides to non-registry sources) are visible in this file, but you should inspect any external/parent scripts referenced by postinstall and avoid running install in directories where ../shared can be tampered with.

Confidence: 85%Severity: 60%
Audit Metadata
Analyzed At
May 7, 2026, 12:57 AM
Package URL
pkg:socket/skills-sh/imgly%2Fagent-skills%2Fbuild%2F@716c7adca218ad22ccce1f728b0598508989138a