iconfont-downloader

Warn

Audited by Socket on Mar 2, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The skill's described behavior aligns with its stated purpose and does not present explicit signs of embedded malicious backdoors in the provided documentation. The main security concerns are: handling of sensitive credentials (in-process cookie extraction), arbitrary file writes (outputPath), processing untrusted scraped content, and transitive supply-chain risk from dynamic imports and browser binary downloads. Recommended mitigations: review the implementation to confirm credentials are not persisted or logged, sanitize and restrict output paths, avoid executing scraped content, run installs in controlled environments, and audit transitive dependencies. Treat this skill as moderately risky until the implementation and runtime behavior (especially cookie/credential handling and any network endpoints) are inspected.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 2, 2026, 10:30 PM
Package URL
pkg:socket/skills-sh/js-mark%2Fsuper-client-r%2Ficonfont-downloader%2F@db70f3ba0c8a64e9bcf593a56ae9ee7291c8e2f1