bruno-api
Warn
Audited by Socket on Sep 5, 2026
1 alert found:
SecuritySecurityevals/fixtures/auth-crud/src/modules/auth/jwt-auth.guard.ts
MEDIUMSecurityMEDIUM
evals/fixtures/auth-crud/src/modules/auth/jwt-auth.guard.ts
The snippet does not show malicious behavior (no exfiltration, backdoor, or obfuscation). However, it constitutes a serious authorization/authentication bypass because the guard always returns `true` and performs no JWT validation. If used in production as-is, it can effectively disable route protection for any endpoints guarded by this class.
Confidence: 82%Severity: 74%
Audit Metadata