github.com / cathrynlavery
cathrynlavery/ diagram-design
HTML·546 files·commit dc1ace4·scanned 1h ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 42,350+ stars — findings likely false positives
verdict accurate?
42,350 stars
Crypto/Web3 project
14% file coverage
threat-state: lowlive
FINDINGS ░▒▓
criticaleval() usage detectedeval() executes arbitrary code and is commonly used in malware to run obfuscated payloads fetched from remote servers.scripts/test-lint-a11y.py
"import-controller": "import('./remote.js');",
"eval-controller": "eval('1 + 1');",
"navigation-controller": "location.assign('https://example.invalid');",
...+8criticalPython dynamic code executioneval(), exec() or compile() on untrusted input can execute arbitrary code. Common in Python malware for running obfuscated payloads.scripts/test-lint-a11y.py
"import-controller": "import('./remote.js');",
"eval-controller": "eval('1 + 1');",
"navigation-controller": "location.assign('https://example.invalid');",
...+7Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
79 files scanned @ dc1ace4 | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution17
network & exfiltration0
file system access0
obfuscation0
supply chain2
owasp / injection0
telemetry
files 79/546rules hit 4engine v6commit dc1ace4
github
cathrynlavery/diagram-design
Editorial diagram design for Claude Code, Codex, and Pi. Self-contained HTML + SVG. No shadows. No Mermaid slop.
42350
2728
162d
546 files
79 scanned(14%)
dc1ace4
architecture░▒▓
entry (0) flagged (1) pkg (33)
103 nodes · 323 edgesscroll to zoom · click node to jump to finding