custom-code-management

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The document correctly describes a Webflow MCP management workflow for inline scripts and aligns conceptually with the provided tool actions. However, permitting arbitrary inline JavaScript with only minimal syntactic validation and providing a non-selective 'delete all' operation present substantial security risks: persistent script-based exfiltration, session/credential theft, trackers/cryptominers, and destructive mass deletion are realistic abuse scenarios. The fragment itself contains no explicit malicious code or obfuscation, but its capabilities make it high-risk in practice. Recommend adding strong operational controls: role-based authorization, explicit approval/audit workflow, static analysis or sandboxing of submitted JS, forced declaration/allowlisting of external endpoints, and safer deletion semantics (selective delete, versioning, or soft-delete).

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 08:31 PM
Package URL
pkg:socket/skills-sh/webflow%2Fwebflow-skills%2Fcustom-code-management%2F@dc7ba59aa18b55d31374e52141388898ef6d5523