constructive

Fail

Audited by Socket on Apr 29, 2026

1 alert found:

Malware
MalwareHIGH
references/cloud-functions.md

The fragment outlines a legitimate, structured approach to building Knative HTTP functions with GraphQL and Postgres access, including PGPM capabilities and dry-run support. However, it bears notable supply-chain and secret-management risks due to environment-based credentials, use of 'latest' dependencies, and a dist-based publishing workflow. To strengthen security, enforce strict secret management, pin dependencies, validate and sanitize logs, and implement access controls around PGPM operations. Overall, the assessment remains cautiously benign with clear mitigations needed for production use.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Apr 29, 2026, 07:06 PM
Package URL
pkg:socket/skills-sh/constructive-io%2Fconstructive-skills%2Fconstructive%2F@3fbbdb7762d06f70b9406a9bac30dadabe043a9d
Security Audit — socket — constructive