constructive-blocks

Warn

Audited by Socket on Aug 27, 2026

1 alert found:

Anomaly
AnomalyLOW
references/install-roots.v1.json

No direct malware or covert malicious behavior is present in this declarative fragment. It documents multiple security-relevant implementation gaps, especially endpoint misrouting, default cross-tenant credential scoping, unconditional localStorage token persistence, missing CSRF support, and incomplete capability or action-shape validation. These are legitimate security warnings requiring mitigation before standalone or multi-tenant authentication and administrative features are trusted.

Confidence: 94%Severity: 68%
Audit Metadata
Analyzed At
Aug 27, 2026, 01:08 PM
Package URL
pkg:socket/skills-sh/constructive-io%2Fconstructive-skills%2Fconstructive-blocks%2F@0702aabad6bc6877c1bdb0d9ab7654021d6528cef007be3c1c7979ea53f1ae00
Security Audit — socket — constructive-blocks