sell

Warn

Audited by Socket on Mar 29, 2026

1 alert found:

Anomaly
AnomalyLOW
templates/unified.html

No clear evidence of intentional malware/backdoor behavior in this fragment. However, there are significant security risks: (1) potential DOM XSS via dangerouslySetInnerHTML using APP_TAGLINE, and (2) increased token leakage risk from placing an OIDC bearer token in the WebSocket URL query string. Additional moderate risk comes from reliance on runtime configuration/globals and broad window-level state exposure, but those are not direct malware indicators.

Confidence: 62%Severity: 62%
Audit Metadata
Analyzed At
Mar 29, 2026, 07:26 PM
Package URL
pkg:socket/skills-sh/popmechanic%2Fvibes-cli%2Fsell%2F@25b1e3d650096017059abc300e237615694c5978