goalflow

Warn

Audited by Socket on Aug 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/security-gate.md

This provided content is a security-gate checklist rather than a dependency code payload. However, it strongly indicates high-impact security issues in referenced modules and deployment practices: (1) a potential exec-based remote code execution path if untrusted DSL/model Python reaches CodeNode while AST guarding is disabled/TODO, (2) insecure/weak API-key handling via md5-derived lookup if used as real auth, and (3) an unsafe/invalid CORS configuration (allow_origins="*" with allow_credentials=True). Separately, it highlights serious supply-chain risk from secrets persisting in git history across forks/mirrors/caches. Verify the referenced implementations directly and treat the exec/DSL path as the primary risk driver.

Confidence: 55%Severity: 62%
Audit Metadata
Analyzed At
Aug 9, 2026, 06:45 AM
Package URL
pkg:socket/skills-sh/akillness%2Fjeo-skills%2Fgoalflow%2F@319a8d687c3e7de7ef45b4d0bdc02a6a8a54b0ca3aa5d0f90338283351cd28d3
Security Audit — socket — goalflow