sharp-edges

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Security
SecurityMEDIUM
references/auth-patterns.md

The fragment provides severe authentication and authorization anti-patterns: IDOR via untrusted user_id object lookups, MFA bypass risks due to frontend-only enforcement and weak/spoofable device-token derivation, and account takeover via predictable, non-invalidated recovery codes with effectively unlimited guessing attempts. There is no clear evidence of supply-chain malware (e.g., payload execution, persistence, exfiltration, or obfuscation); the risk is extremely high from broken authz/authn design if implemented as shown.

Confidence: 70%Severity: 90%
Audit Metadata
Analyzed At
Sep 4, 2026, 01:52 PM
Package URL
pkg:socket/skills-sh/craftos-dev%2Fcraftbot%2Fsharp-edges%2F@859fc8dd7cfbcf97373c631c4bbb219aa5dd1d45e4ba3c699696e24909e998d6
Security Audit — socket — sharp-edges