insight-pdf

Warn

Audited by Socket on Mar 5, 2026

1 alert found:

Security
SecurityMEDIUM
package.json

The install script and dependency are not directly executing arbitrary remote JavaScript, shelling out to unknown hosts, or using insecure HTTP references, so there's no immediate evidence of active malware. However, the postinstall step causes automated download and installation of browser binaries and may execute package install hooks from Playwright or its transitive dependencies. This introduces supply-chain risk: a malicious or compromised Playwright release (or a compromise of its binary distribution) could result in remote code execution, telemetry/data exfiltration, or other unwanted behavior during install. Review and pin trusted Playwright versions, verify checksums or use an allowlist for binaries if possible, and audit the Playwright package and its install logs when installing in sensitive environments.

Confidence: 80%Severity: 70%
Audit Metadata
Analyzed At
Mar 5, 2026, 07:04 PM
Package URL
pkg:socket/skills-sh/wghust%2Fstark-skills%2Finsight-pdf%2F@817d57a518d26e35e8cf61174ff70c5c788b53fe