renaissance-md-html

Warn

Audited by Socket on Apr 7, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/md_to_renaissance_html.mjs

No clear evidence of intentional malware/backdoors in this module. However, the code has multiple high-impact supply-chain security weaknesses when processing untrusted Markdown: it can perform arbitrary build-time outbound HTTP fetches to attacker-specified URLs (SSRF/internal access risk) and can read arbitrary local files during image embedding due to path resolution without baseDir containment checks (LFI/path traversal disclosure risk). Separately, it embeds marked.parse output into the final HTML without explicit sanitization, creating a potential XSS risk in any environment where the generated HTML is rendered or shared.

Confidence: 78%Severity: 85%
Audit Metadata
Analyzed At
Apr 7, 2026, 07:36 PM
Package URL
pkg:socket/skills-sh/shadowcz007%2Fskills%2Frenaissance-md-html%2F@a774db9b1a331cf4f90b753ff37c2b3003eebf61