svg-hand-drawn-preview

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Security
SecurityMEDIUM
assets/player.js

Overall, the code is an in-browser animation widget with no direct evidence of malware (no network/exfiltration/backdoor logic). However, it directly injects caller-provided `svgMarkup` into the DOM via `innerHTML` without sanitization or allowlisting, creating a high-impact DOM XSS/active-content risk if the markup is not fully trusted and constrained by strong CSP/sanitization upstream. Treat supply-chain usage as unsafe unless `svgMarkup` is strictly controlled.

Confidence: 78%Severity: 80%
Audit Metadata
Analyzed At
Apr 14, 2026, 08:02 AM
Package URL
pkg:socket/skills-sh/shaom%2Fsvg-hand-drawn-skill%2Fsvg-hand-drawn-preview%2F@8cdbd353256c19db3d465838afe0015351b5382b