mermaid

Warn

Audited by Socket on Feb 12, 2026

1 alert found:

Anomaly
AnomalyLOW
tools/validate.sh

The script itself contains no direct malicious payloads, but it performs risky operations that allow untrusted code to run: it uses npx to install/run remote packages and uses a fragile PATH-derived require to load 'beautiful-mermaid'. These patterns make it moderately risky from a supply-chain perspective because a compromised npm package or manipulated PATH can lead to arbitrary code execution. Use caution: pin and vend dependencies or avoid runtime npx installs and fix the module require to use standard resolution.

Confidence: 80%Severity: 50%
Audit Metadata
Analyzed At
Feb 12, 2026, 05:56 PM
Package URL
pkg:socket/skills-sh/mitsuhiko%2Fagent-commands%2Fmermaid%2F@0d4d0a3da84a1f936740b58dd8e95c11a9ba486f