express-production

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Anomaly
AnomalyLOW
references/middleware-patterns.md

No evidence of intentional malicious behavior or obfuscation is present. The principal security concern is unsafe cache-key design: URL-only and page-only keys can cause cross-user or cross-authorization response disclosure when endpoints are personalized. The conditional cache also lacks cache error handling. Review cache usage and include an appropriate user, tenant, authorization, or privacy context in keys, or disable caching for personalized responses.

Confidence: 94%Severity: 58%
Audit Metadata
Analyzed At
Sep 16, 2026, 03:23 AM
Package URL
pkg:socket/skills-sh/bobmatnyc%2Fclaude-mpm-skills%2Fexpress-production%2F@5e5be62c801e0fae54db96258fab94e8b1fb8db5c17679f0bd9cd65d5caed2fc
Security Audit — socket — express-production