security-documentation

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
references/1-secure-coding-practices.md

The fragment is primarily educational secure-coding guidance and contains no evident malware or supply-chain backdoor. The createUserBad example is intentionally vulnerable to SQL injection and must not be used. The CSP configuration is weaker than recommended because it permits unsafe-inline. The parameterized query and DOMPurify allowlist provide appropriate protections in the corresponding secure examples.

Confidence: 99%Severity: 72%
Audit Metadata
Analyzed At
Sep 16, 2026, 10:47 AM
Package URL
pkg:socket/skills-sh/aj-geddes%2Fuseful-ai-prompts%2Fsecurity-documentation%2F@58fa43f7de76b44df9b98ef7a8f7c3ed29f935dda780d2e524a260f4f8b62353
Security Audit — socket — security-documentation