frontend-architect

Warn

Audited by Socket on Sep 18, 2026

1 alert found:

Anomaly
AnomalyLOW
references/internal-tools.md

No clear malware or intentional malicious behavior is present. The code is readable internal-tool architecture with normal authentication, feature-flag, debugging, and deployment functions. Security concerns include a broken public-route-group check, incomplete proof of JWT and downstream identity handling, possible feature-flag IDOR due to client-controlled email and flag values, lack of visible CSRF and input validation, sensitive debug-log exposure, and mutable third-party GitHub Action usage with privileged deployment secrets. The omitted API handlers and Cloudflare configuration must be reviewed before deployment.

Confidence: 94%Severity: 62%
Audit Metadata
Analyzed At
Sep 18, 2026, 12:14 AM
Package URL
pkg:socket/skills-sh/curiositech%2Fsome_claude_skills%2Ffrontend-architect%2F@be333c7581fa465eff84e8971938d6caada1f2366cc4c4b5ba5a619cf63fddbd
Security Audit — socket — frontend-architect