constructive-blocks
Warn
Audited by Socket on Aug 27, 2026
1 alert found:
AnomalyAnomalyreferences/install-roots.v1.json
LOWAnomalyLOW
references/install-roots.v1.json
No direct malware or covert malicious behavior is present in this declarative fragment. It documents multiple security-relevant implementation gaps, especially endpoint misrouting, default cross-tenant credential scoping, unconditional localStorage token persistence, missing CSRF support, and incomplete capability or action-shape validation. These are legitimate security warnings requiring mitigation before standalone or multi-tenant authentication and administrative features are trusted.
Confidence: 94%Severity: 68%
Audit Metadata