apollo-server

Warn

Audited by Socket on Sep 15, 2026

1 alert found:

Anomaly
AnomalyLOW
references/plugins.md

The code is a conventional Apollo Server plugin configuration with no evidence of malware or supply-chain sabotage. The primary security concern is the explicit forwarding of all request headers and GraphQL variable values to Apollo Studio, which may leak secrets or personal data if requests contain them. Header and variable redaction should be configured before production use.

Confidence: 98%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 07:26 AM
Package URL
pkg:socket/skills-sh/apollographql%2Fskills%2Fapollo-server%2F@d5e6a54c01634fccd07f542bfff4b8b73e5855f3fbc8db403d75191f8c1ca759
Security Audit — socket — apollo-server