bruno-api

Warn

Audited by Socket on Sep 5, 2026

1 alert found:

Security
SecurityMEDIUM
evals/fixtures/auth-crud/src/modules/auth/jwt-auth.guard.ts

The snippet does not show malicious behavior (no exfiltration, backdoor, or obfuscation). However, it constitutes a serious authorization/authentication bypass because the guard always returns `true` and performs no JWT validation. If used in production as-is, it can effectively disable route protection for any endpoints guarded by this class.

Confidence: 82%Severity: 74%
Audit Metadata
Analyzed At
Sep 5, 2026, 03:08 PM
Package URL
pkg:socket/skills-sh/beerjoa%2Fskills%2Fbruno-api%2F@c2c9ef72e6e8e3402e13b8bbd79943cf308f5e3c8f5f1539cce0861fcb20d496
Security Audit — socket — bruno-api